
Wikipedia Anniversaries Security & Risk Analysis
wordpress.org/plugins/wikipedia-anniversariesWikipedia Anniversaries is a widget that lets your visitors to see important history dates from Wikipedia.
Is Wikipedia Anniversaries Safe to Use in 2026?
Generally Safe
Score 85/100Wikipedia Anniversaries has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wikipedia-anniversaries" v1.2.1 plugin presents a mixed security posture. On one hand, it demonstrates good practices by having zero known CVEs, a complete absence of SQL injection vulnerabilities due to the use of prepared statements, and no observed taint flows, indicating a generally clean codebase in these areas. The lack of external HTTP requests and zero file operations (though noted as 4 in code signals, the lack of external HTTP requests and no taint suggests these might be internal or benign operations) also contribute positively to its security profile.
However, significant concerns arise from the static analysis. The presence of the deprecated `create_function` is a potential security risk, as it can be exploited in certain contexts. More critically, a complete absence of output escaping for all 21 detected outputs is a major vulnerability. This leaves the plugin wide open to Cross-Site Scripting (XSS) attacks, where malicious scripts could be injected into the WordPress site through the plugin's output. Furthermore, the lack of any nonce checks or capability checks across all entry points means that even if entry points existed (which are reported as zero), they would be completely unprotected against unauthorized access or manipulation.
Given the lack of vulnerability history and the absence of taint flows, it's possible that the plugin's limited functionality or implementation details currently prevent exploitation of the identified weaknesses. However, the combination of `create_function` and the pervasive lack of output escaping creates a strong theoretical basis for severe security flaws, particularly XSS. The absence of any authentication or authorization checks on potential entry points (though none are currently identified) also represents a significant underlying weakness that could be exploited if functionality is added or changed in future versions.
Key Concerns
- All outputs unescaped (XSS risk)
- Dangerous function used (create_function)
- No capability checks on entry points
- No nonce checks on entry points
Wikipedia Anniversaries Security Vulnerabilities
Wikipedia Anniversaries Code Analysis
Dangerous Functions Found
Output Escaping
Wikipedia Anniversaries Attack Surface
WordPress Hooks 2
Maintenance & Trust
Wikipedia Anniversaries Maintenance & Trust
Maintenance Signals
Community Trust
Wikipedia Anniversaries Alternatives
Wikipedia Widget
wikipedia-widget
Shows a simple Ajax based Wikipedia search-formular and the results for the current post/page title or default keywords.
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Wikipedia Anniversaries Developer Profile
6 plugins · 80 total installs
How We Detect Wikipedia Anniversaries
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wikipedia-anniversaries/style-wiki-this-day.cssplugins/wikipedia-anniversaries/style-wiki-this-day.css?ver=