
TDLC Birthdays Security & Risk Analysis
wordpress.org/plugins/tdlc-birthdaysA simple BuddyPress plugin displaying the birthday of members in a sidebar Widget. 9 languages, many options available. Check out the description :)
Is TDLC Birthdays Safe to Use in 2026?
Generally Safe
Score 92/100TDLC Birthdays has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tdlc-birthdays" v1.1.0 plugin exhibits a generally positive security posture based on the static analysis and vulnerability history provided. The absence of any known vulnerabilities, including critical or high severity ones, and the lack of recorded past issues suggest a commitment to secure coding practices. The code analysis reveals a relatively small attack surface with no identified AJAX handlers, REST API routes, or shortcodes that are directly exposed to potential attackers. Furthermore, the absence of file operations and external HTTP requests reduces the likelihood of certain types of attacks. The plugin also utilizes nonce checks, which is a good practice for preventing CSRF attacks. However, there are areas that warrant attention. A significant concern is the relatively low percentage of properly escaped output (54%), which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before being displayed. While the total number of SQL queries is manageable, 43% of them are not using prepared statements, posing a risk of SQL injection if any of these queries are susceptible to malicious input. The lack of capability checks on the entry points, although currently there are no unprotected entry points, could be a weakness if new ones are added in the future without proper authorization controls. The presence of cron events, while not directly an attack vector, represents potential execution points that should be monitored.
Key Concerns
- Low percentage of properly escaped output
- Significant SQL queries not using prepared statements
- Lack of capability checks on entry points
TDLC Birthdays Security Vulnerabilities
TDLC Birthdays Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
TDLC Birthdays Attack Surface
WordPress Hooks 8
Scheduled Events 2
Maintenance & Trust
TDLC Birthdays Maintenance & Trust
Maintenance Signals
Community Trust
TDLC Birthdays Alternatives
Wbcom Designs – Birthday Widget for BuddyPress
birthday-widget-for-buddypress
Display upcoming birthdays of BuddyPress members with a beautiful, responsive widget that integrates seamlessly with any WordPress theme.
bbPress Login Register Links On Forum Topic Pages
bbpress-login-register-links-on-forum-topic-pages
Add bbPress only sidebar, Add bbpress login link, bbpress register link, forget password link, log out link in bbpress forum index pages or bbpress si …
BP Group Documents
bp-group-documents
BP Group Documents creates a page within each BuddyPress group to upload and any type of file or document.
BuddyPress Notification Widget
buddypress-notifications-widget
BuddyPress notification widget allow site admins to show BuddyPress user notification in widget.
BuddyPress Sitewide Activity Widget
buddypress-sitewide-activity-widget
BuddyPress Sitewide Activity Widget allows you to use BuddyPress Sitewide activity stream as a widget.
TDLC Birthdays Developer Profile
20 plugins · 640 total installs
How We Detect TDLC Birthdays
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tdlc-birthdays/tdlc-birthdays.php/wp-content/plugins/tdlc-birthdays/core.php/wp-content/plugins/tdlc-birthdays/includes/settings-class.php/wp-content/plugins/tdlc-birthdays/includes/tdlc-mail-send-class.php