
Todayish in History Security & Risk Analysis
wordpress.org/plugins/todayish-in-historyShows a list of links to posts from previous years on or near this date, 1 per year. Provides a function to use in a theme, as well as a widget
Is Todayish in History Safe to Use in 2026?
Generally Safe
Score 85/100Todayish in History has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "todayish-in-history" plugin version 0.2 presents a mixed security posture. On the positive side, the absence of known CVEs and a clean taint analysis report suggest a general lack of critical, easily exploitable vulnerabilities and a well-managed vulnerability history. The plugin also exhibits good practices by utilizing prepared statements for all SQL queries and refraining from external HTTP requests or file operations, which limits common attack vectors.
However, several concerns in the static analysis warrant attention. The presence of the `create_function` function, a deprecated and often insecure PHP construct, poses a potential risk as it can lead to code injection if used with user-supplied input, though the current static analysis does not reveal any direct exploitable flows. Furthermore, a significant portion of output (66%) is not properly escaped, indicating a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce and capability checks across all entry points, combined with the absence of authentication checks on any AJAX handlers or permission callbacks for REST API routes (though none exist in this version), is a critical oversight that leaves potential future or undiscovered entry points highly vulnerable.
In conclusion, while the plugin benefits from a clean vulnerability history and responsible SQL handling, the unescaped output and lack of authentication/authorization checks represent significant weaknesses. The presence of `create_function` is a technical debt that should be addressed. Addressing these issues will be crucial for improving the plugin's overall security.
Key Concerns
- Unescaped output detected
- Dangerous function 'create_function' found
- Missing nonce checks
- Missing capability checks
Todayish in History Security Vulnerabilities
Todayish in History Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Todayish in History Attack Surface
WordPress Hooks 2
Maintenance & Trust
Todayish in History Maintenance & Trust
Maintenance Signals
Community Trust
Todayish in History Alternatives
One Click Demo Import
one-click-demo-import
Import your demo content, widgets and theme settings with one click. Theme authors! Enable simple theme demo import for your users.
Advanced Import: One-Click Demo Import for WordPress
advanced-import
Advanced Import simplifies importing demo data for WordPress sites, enabling users to import posts, pages, media, widgets, customizer settings, and Gu …
Hello Plus
hello-plus
Hello+ is a free WordPress plugin designed to work seamlessly with Elementor’s Hello suite of themes.
Themesflat Addons For Elementor
themesflat-addons-for-elementor
Themesflat Addons For Elementor plugin you install after Elementor!. Themesflat addon focuses on support for the author build Template Kits
Meks ThemeForest Smart Widget
meks-themeforest-smart-widget
Easily display ThemeForest items inside WordPress widget.
Todayish in History Developer Profile
4 plugins · 150 total installs
How We Detect Todayish in History
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/todayish-in-history/todayish_in_history.cssHTML / DOM Fingerprints
todayinhistorynotwidgettitleid="todayinhistory"id="historylabel"<div id='todayinhistory' class='horizontal'><div id='todayinhistory' class='vertical'><h2 id='historylabel' class='notwidgettitle'>