
Title Year ShortCode Security & Risk Analysis
wordpress.org/plugins/title-year-shortcodeA simple and nice plugin to echo the current year to your page or post title using a shortcode, as simple as that.
Is Title Year ShortCode Safe to Use in 2026?
Generally Safe
Score 100/100Title Year ShortCode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "title-year-shortcode" v1.0.1 plugin exhibits a generally strong security posture based on the provided static analysis. It adheres to good development practices by not utilizing dangerous functions, all SQL queries are prepared statements, and all outputs are properly escaped. Furthermore, there are no file operations or external HTTP requests, significantly reducing potential attack vectors. The absence of any recorded vulnerabilities, past or present, in the vulnerability history is also a positive indicator.
Despite these strengths, a notable concern arises from the complete lack of nonce and capability checks across all entry points, including its single shortcode. While the static analysis did not reveal specific taint flows or dangerous function usage that would immediately exploit this, the absence of these fundamental security mechanisms represents a significant weakness. This could potentially allow for Cross-Site Request Forgery (CSRF) attacks if the shortcode's functionality were to be modified in future versions or if it interacted with user-modifiable data without proper validation. The attack surface, though small, is entirely unprotected at the capability check level.
In conclusion, the plugin demonstrates a commitment to secure coding practices regarding data handling and output. However, the lack of authorization checks on its shortcode is a critical oversight that needs to be addressed. The clean vulnerability history is encouraging, but it does not negate the inherent risk posed by unprotected entry points.
Key Concerns
- Missing capability checks on shortcode
- Missing nonce checks on shortcode
Title Year ShortCode Security Vulnerabilities
Title Year ShortCode Release Timeline
Title Year ShortCode Code Analysis
Title Year ShortCode Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Title Year ShortCode Maintenance & Trust
Maintenance Signals
Community Trust
Title Year ShortCode Alternatives
Current Year, Symbols and IP Shortcode
current-year-shortcode
Useful shortcode for WordPress. Current year, copyright, symbols and user IP with shortcode.
Current Year and Footer Information
current-year-and-footer-information
Easy plugin to show the Copyright information, Current Year, Legal Notice and Cookies Policy. Compatible with WordPress Multilanguage.
Current Year By Nasim
current-year-by-nasim
A lightweight plugin to show the current year anywhere using the [cyb_nasim] shortcode. Perfect for copyright footers.
Copyright shortcode creator VICT
copyright-shortcode-creator-vict
Shortcodes to show the current year, the copyright logo and/or the sitename wherever you want it.
Current Date Free
current-date-free
A lightweight plugin that provides shortcodes for the current, Year, Month, Day, Time and more.
Title Year ShortCode Developer Profile
3 plugins · 100 total installs
How We Detect Title Year ShortCode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[year]