
Show/Hide Content at Set Time Security & Risk Analysis
wordpress.org/plugins/shortcodes-to-show-or-hide-contentShortcodes to wrap around text, which specify at what date or time that content should appear or disappear, either once, or on a recurring basis.
Is Show/Hide Content at Set Time Safe to Use in 2026?
Generally Safe
Score 85/100Show/Hide Content at Set Time has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shortcodes-to-show-or-hide-content" plugin version 2.5 exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities, unescaped output, file operations, external HTTP requests, and any taint analysis findings indicates that the code has been developed with security best practices in mind. The fact that all SQL queries utilize prepared statements is a significant strength.
However, the analysis highlights some potential areas for improvement. The plugin has a total of 7 shortcodes, which represent its primary attack surface. While the static analysis reports 0 unprotected entry points, the lack of explicit nonce and capability checks mentioned for these shortcodes is a concern. This could potentially leave the plugin vulnerable if the shortcodes themselves accept user-controlled input that is not adequately validated and authorized before being processed. The absence of recorded vulnerabilities in its history is a positive sign, suggesting a history of secure development, but it does not negate the need for robust security checks on its active entry points.
In conclusion, the plugin demonstrates a good foundation with its secure coding practices regarding SQL and output handling. The primary weakness lies in the potential for insufficient authorization checks on its shortcodes, which represent the main interaction points with the plugin. Addressing this by implementing appropriate nonce and capability checks would further strengthen its security.
Key Concerns
- No Nonce Checks Implemented
- No Capability Checks Implemented
Show/Hide Content at Set Time Security Vulnerabilities
Show/Hide Content at Set Time Code Analysis
Output Escaping
Show/Hide Content at Set Time Attack Surface
Shortcodes 7
Maintenance & Trust
Show/Hide Content at Set Time Maintenance & Trust
Maintenance Signals
Community Trust
Show/Hide Content at Set Time Alternatives
Date Time Picker for Contact Form 7
date-time-picker-for-contact-form-7
This plugin enables Contact Form 7 text field into a Date picker, Time picker or Date Time picker by using CSS class.
Countdown Timer Ultimate
countdown-timer-ultimate
A quick, easy way to add and display responsive Countdown timer on your website. Also work with Gutenberg shortcode block.
Meks Time Ago
meks-time-ago
Automatically change your post date display to "time ago" format like 1 hour ago, 3 days ago, etc...
Order Delivery Date for WooCommerce
order-delivery-date-for-woocommerce
Let customers choose delivery dates & times on checkout. Simplify delivery management by blocking holidays & setting max deliveries per day.
WP Date and Time Shortcode
wp-date-and-time-shortcode
Shortcode to show any current, past, and future date or time. Display this, previous, or next year, month, day, etc.
Show/Hide Content at Set Time Developer Profile
4 plugins · 10K total installs
How We Detect Show/Hide Content at Set Time
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shortcodes-to-show-or-hide-content/includes/shortcodes.php/wp-content/plugins/shortcodes-to-show-or-hide-content/includes/retired-shortcodes.phpshortcodes-to-show-or-hide-content/style.css?ver=shortcodes-to-show-or-hide-content/script.js?ver=HTML / DOM Fingerprints
Copyright 2016 Dave Clements (email : https://www.theukedge.com/contact/)This program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License, version 2, aspublished by the Free Software Foundation.+15 moredata-shortcode-id[time-restrict][time-restrict-repeat][expires][showafter]