
Today's Date Inserter Security & Risk Analysis
wordpress.org/plugins/todays-date-inserterSimply and quickly add the current date and or time to your wordpress posts or pages using a shortcode Date widget also included
Is Today's Date Inserter Safe to Use in 2026?
Use With Caution
Score 63/100Today's Date Inserter has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "todays-date-inserter" plugin v1.2.1 exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by having no dangerous functions, no raw SQL queries, and no file operations or external HTTP requests. The limited attack surface, consisting of a single shortcode, is also a strength. However, significant concerns arise from the code signals and vulnerability history. A substantial portion of output (73%) is not properly escaped, creating a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the absence of nonce checks and capability checks on its single entry point (the shortcode) means any user, regardless of their role, could potentially trigger unintended actions or inject malicious code if the shortcode's output is not handled securely by the theme or other plugins. The vulnerability history reveals a past medium-severity XSS vulnerability that is currently unpatched, indicating a recurring issue with input sanitization and output escaping. This unpatched vulnerability, combined with the high rate of unescaped output, suggests a pattern of incomplete security patching and ongoing risks.
In conclusion, while the plugin avoids common pitfalls like raw SQL and dangerous functions, the high rate of unescaped output and the presence of an unpatched XSS vulnerability are critical weaknesses. The lack of security checks on the shortcode further exacerbates these risks. Users should exercise caution and prioritize updating or replacing this plugin, especially given the unpatched vulnerability.
Key Concerns
- Unpatched CVE (Medium Severity)
- High rate of unescaped output (73%)
- Missing nonce checks on shortcode
- Missing capability checks on shortcode
Today's Date Inserter Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Today's Date Inserter <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Today's Date Inserter Code Analysis
Output Escaping
Today's Date Inserter Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Today's Date Inserter Maintenance & Trust
Maintenance Signals
Community Trust
Today's Date Inserter Alternatives
Date Tool
date-tool
A simple plugin that returns the current date/time in a variety of different ways.
Today's Date
todays-date
Display The Current Date In A Customizable Format
EZ current date
ezdate
This plugin will show your current month and year, also you have the option select to show only the Month or only the Year;
Shortcode for Current Date
shortcode-for-current-date
Insert current Date, Month or Year anywhere in your WordPress site with a simple shortcode.
Current Date Shortcode For WordPess
current-date
Easily display the current date anywhere using a simple shortcode, Gutenberg block, Elementor addon
Today's Date Inserter Developer Profile
1 plugin · 800 total installs
How We Detect Today's Date Inserter
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
lfo_todays_date_widget_class[todaysdate][todaysdate format=