
LAPDI On This Day Security & Risk Analysis
wordpress.org/plugins/tsp-on-this-dayOn This Day allows you to view blog posts with the same month and day in history on your blog (similar to Facebook's "On This Day" app).
Is LAPDI On This Day Safe to Use in 2026?
Generally Safe
Score 85/100LAPDI On This Day has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "tsp-on-this-day" plugin v1.0.8 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL queries (even prepared ones), file operations, or external HTTP requests is commendable. Furthermore, the lack of recorded vulnerabilities or CVEs in its history suggests a history of responsible development and maintenance. The presence of a nonce check and the complete absence of exploitable taint flows are also positive indicators.
However, the analysis reveals a significant concern regarding output escaping. With one output identified and 0% properly escaped, this indicates a potential for Cross-Site Scripting (XSS) vulnerabilities. If user-controlled data is displayed without proper sanitization, an attacker could inject malicious scripts. While the attack surface is currently zero and there are no identified capability checks missing, this single unescaped output represents a tangible risk that needs immediate attention. The plugin's historical lack of vulnerabilities might be misleading if this output escaping issue has been present and undetected or unaddressed. Therefore, while the plugin has many strengths, the unescaped output is a critical weakness that elevates its risk profile.
Key Concerns
- Output escaping is 0% proper
LAPDI On This Day Security Vulnerabilities
LAPDI On This Day Code Analysis
Output Escaping
LAPDI On This Day Attack Surface
WordPress Hooks 1
Maintenance & Trust
LAPDI On This Day Maintenance & Trust
Maintenance Signals
Community Trust
LAPDI On This Day Alternatives
No alternatives data available yet.
LAPDI On This Day Developer Profile
7 plugins · 220 total installs
How We Detect LAPDI On This Day
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tsp-on-this-day/assets/css/movingboxes.css/wp-content/plugins/tsp-on-this-day/assets/css/movingboxes-ie.css/wp-content/plugins/tsp-on-this-day/tsp-on-this-day.ie.css/wp-content/plugins/tsp-on-this-day/tsp-on-this-day.css/wp-content/plugins/tsp-on-this-day/assets/js/jquery.movingboxes.js/wp-content/plugins/tsp-on-this-day/assets/js/slider-scripts.js/wp-content/plugins/tsp-on-this-day/assets/js/scripts.js/wp-content/plugins/tsp-on-this-day/assets/js/jquery.movingboxes.js/wp-content/plugins/tsp-on-this-day/assets/js/slider-scripts.js/wp-content/plugins/tsp-on-this-day/assets/js/scripts.js/wp-content/plugins/tsp-on-this-day/assets/css/movingboxes.css?ver=/wp-content/plugins/tsp-on-this-day/assets/css/movingboxes-ie.css?ver=/wp-content/plugins/tsp-on-this-day/tsp-on-this-day.ie.css?ver=/wp-content/plugins/tsp-on-this-day/tsp-on-this-day.css?ver=/wp-content/plugins/tsp-on-this-day/assets/js/jquery.movingboxes.js?ver=/wp-content/plugins/tsp-on-this-day/assets/js/slider-scripts.js?ver=/wp-content/plugins/tsp-on-this-day/assets/js/scripts.js?ver=HTML / DOM Fingerprints
tsp-on-this-day-widget<!-- LAPDI On This Day Widget -->data-max-wordsdata-show-authordata-show-event-datadata-show-privatedata-read-more-textdata-no-posts-msg+5 more[tsp-on-this-day]