
Website Diary Security & Risk Analysis
wordpress.org/plugins/website-diaryFor keeping diary-like notes, so you can quickly overview recent changes on your site (and spot the source of an eventual problem).
Is Website Diary Safe to Use in 2026?
Generally Safe
Score 85/100Website Diary has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "website-diary" plugin version 0.9.1 presents a mixed security posture. On one hand, the lack of identified CVEs and a clean vulnerability history are positive indicators, suggesting a history of reasonable security. The static analysis also shows a small attack surface with no identified unprotected entry points and a decent number of nonce and capability checks. However, significant concerns arise from the code analysis. The complete absence of prepared statements for six SQL queries is a critical flaw, exposing the plugin to SQL injection vulnerabilities. Furthermore, the fact that 100% of its 14 output operations are not properly escaped creates a high risk of Cross-Site Scripting (XSS) attacks. While the taint analysis did not reveal critical or high severity issues, the presence of one flow with unsanitized paths warrants attention. The plugin demonstrates good practice in avoiding dangerous functions, file operations, and external HTTP requests, but the fundamental weaknesses in handling SQL and output escaping overshadow these strengths, making it a high-risk plugin in its current state.
Key Concerns
- SQL queries lack prepared statements
- Output escaping is missing
- Unsanitized path in taint flow
Website Diary Security Vulnerabilities
Website Diary Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Website Diary Attack Surface
WordPress Hooks 2
Maintenance & Trust
Website Diary Maintenance & Trust
Maintenance Signals
Community Trust
Website Diary Alternatives
BugHerd
bugherd
BugHerd is the visual feedback tool for websites.
UserView
userview
Logs user activities like profile updates, additions, and deletions, offering a dashboard for easy viewing and management.
LightStart – Maintenance Mode, Coming Soon and Landing Page Builder
wp-maintenance-mode
Easy Drag & Drop Page Builder that adds a splash page to your site that it's perfect for a coming soon page, maintenance or landing page.
Adminimize
adminimize
Adminimize that lets you hide 'unnecessary' items from the WordPress backend
Remove Dashboard Access
remove-dashboard-access-for-non-admins
Disable Dashboard access for users of a specific role or capability. Disallowed users are redirected to a chosen URL. Get set up in seconds.
Website Diary Developer Profile
4 plugins · 420 total installs
How We Detect Website Diary
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/website-diary/style.csswebsite-diary/style.css?ver=HTML / DOM Fingerprints
webDiary_mainwebdiary