Quote of the Day by Quotations Book Security & Risk Analysis

wordpress.org/plugins/quotations-book-quotes-of-the-day

This plugin lets you add a Quote of the Day widget to your WordPress page.

10 active installs v1.0 PHP + WP 3.0.1+ Updated Oct 14, 2014
famous-quotesquotationsquotequote-of-the-dayquotes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Quote of the Day by Quotations Book Safe to Use in 2026?

Generally Safe

Score 85/100

Quote of the Day by Quotations Book has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "quotations-book-quotes-of-the-day" plugin version 1.0, based on the provided static analysis, exhibits a concerning security posture despite the absence of identified vulnerabilities in its history. The most significant concern is the complete lack of output escaping, meaning that any data outputted by the plugin is not properly sanitized, leaving it vulnerable to Cross-Site Scripting (XSS) attacks. While the plugin does not appear to have a large attack surface with no registered AJAX handlers, REST API routes, shortcodes, or cron events, the lack of authentication and capability checks on these potential entry points (though none are currently present) is a latent risk should they be introduced in future versions or if the analysis is incomplete. The plugin's history of zero known vulnerabilities and a clean taint analysis are positive indicators, but they are overshadowed by the critical issue of unescaped output, which presents a clear and present danger to users.

Key Concerns

  • No output escaping found
  • No capability checks on entry points
  • No nonce checks on entry points
Vulnerabilities
None known

Quote of the Day by Quotations Book Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Quote of the Day by Quotations Book Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped7 total outputs
Attack Surface

Quote of the Day by Quotations Book Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initqb_widget.php:111
Maintenance & Trust

Quote of the Day by Quotations Book Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedOct 14, 2014
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Quote of the Day by Quotations Book Developer Profile

quotationsbook

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Quote of the Day by Quotations Book

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
http://quotationsbook.com/

HTML / DOM Fingerprints

CSS Classes
widget-containerwidget-title
Data Attributes
id="foo_widget"name="qtype"
Shortcode Output
<script type="text/javascript" src="http://quotationsbook.com/<small><i><a href="http://quotationsbook.com/services/" target="_blank">more Quotes</a></i></small>
FAQ

Frequently Asked Questions about Quote of the Day by Quotations Book