Wajeez OTD Security & Risk Analysis

wordpress.org/plugins/wajeez-otd

A quick and light plugin that shows previous blog posts published on this date in past years.

10 active installs v2.0.0 PHP 7.0+ WP 4.0+ Updated Unknown
historynostalgiaonthisdayotdwidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Wajeez OTD Safe to Use in 2026?

Generally Safe

Score 100/100

Wajeez OTD has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "wajeez-otd" v2.0.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface. Furthermore, the code signals indicate a commendable practice of using prepared statements for all SQL queries and a generally good approach to output escaping, with only a small percentage of outputs needing attention. The lack of reported vulnerabilities in its history further reinforces this positive assessment.

Despite the overall strong security, the complete lack of nonce checks and capability checks, coupled with the high percentage of unescaped outputs (29%), presents a potential concern. While the current analysis did not reveal any direct vulnerabilities stemming from these areas, these are fundamental security controls that, if not addressed, could become vectors for exploitation in future updates or under different attack scenarios. The absence of taint analysis results could also mean that complex data flows were not deeply scrutinized, or that there were simply no sensitive flows to report. Therefore, while "wajeez-otd" v2.0.0 appears secure in its current state, diligent attention to the identified areas for improvement is recommended.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Significant portion of unescaped output
Vulnerabilities
None known

Wajeez OTD Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Wajeez OTD Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
24 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

71% escaped34 total outputs
Attack Surface

Wajeez OTD Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedwajeezotd.php:41
actionadmin_menuwajeezotd.php:47
filterplugin_action_linkswajeezotd.php:55
actionadmin_initwajeezotd.php:67
actionwp_enqueue_scriptswajeezotd.php:83
actionadmin_enqueue_scriptswajeezotd.php:84
actionadmin_noticeswajeezotd.php:92
actionwidgets_initwajeezotd.php:236
Maintenance & Trust

Wajeez OTD Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.0
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Wajeez OTD Developer Profile

Raouf Shabayek

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Wajeez OTD

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wajeez-otd/wajeez.css/wp-content/plugins/wajeez-otd/admin-rtl.css
Version Parameters
wajeez-otd/wajeez.css?ver=wajeez-otd-ar/admin-rtl.css?ver=

HTML / DOM Fingerprints

CSS Classes
wajeez-otdwajeez-thumbwajeez-meta
Data Attributes
class="near-match"
FAQ

Frequently Asked Questions about Wajeez OTD