
Wordnik Word of the Day Widget Security & Risk Analysis
wordpress.org/plugins/wordnik-word-of-the-day-widgetSimple widget for displaying the current Word of the Day from the Wordnik API
Is Wordnik Word of the Day Widget Safe to Use in 2026?
Generally Safe
Score 85/100Wordnik Word of the Day Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'wordnik-word-of-the-day-widget' plugin version 0.2 exhibits a mixed security posture. On the positive side, the absence of known CVEs and the fact that all SQL queries utilize prepared statements are strong indicators of good development practices in these areas. The plugin also shows no signs of critical or high-severity taint flows, and a lack of file operations and external HTTP requests contributes to a reduced attack surface in those respects.
However, there are notable concerns. The use of the `create_function` is a significant risk, as this function is deprecated and can be a vector for code injection if not handled with extreme care and sanitization, which is not evident here. Furthermore, the plugin demonstrates very poor output escaping practices, with only 13% of outputs being properly escaped. This high percentage of unescaped output presents a substantial risk of cross-site scripting (XSS) vulnerabilities. The lack of nonce checks and capability checks on potential entry points, although currently zero, indicates a potential oversight in securing future code additions.
Given the clean vulnerability history, it suggests that past versions may have been developed with reasonable security in mind, or that its limited functionality and attack surface have not attracted significant malicious attention. However, the identified code signals, particularly the `create_function` and the widespread unescaped output, represent clear and present dangers that outweigh the positive aspects. The plugin's current state requires immediate attention to mitigate the risks of XSS and potential code injection.
Key Concerns
- Use of dangerous function: create_function
- Low output escaping percentage
- Missing nonce checks
- Missing capability checks
Wordnik Word of the Day Widget Security Vulnerabilities
Wordnik Word of the Day Widget Release Timeline
Wordnik Word of the Day Widget Code Analysis
Dangerous Functions Found
Output Escaping
Wordnik Word of the Day Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Wordnik Word of the Day Widget Maintenance & Trust
Maintenance Signals
Community Trust
Wordnik Word of the Day Widget Alternatives
CM Tooltip Glossary
enhanced-tooltipglossary
Transform jargon into engaging content that boosts SEO, drives engagement, improves conversions, with automatic links and tooltips.
Heroic Glossary – Block for building Glossaries, Dictionaries and more
heroic-glossary
The best WordPress glossary builder plugin to create and manage your own glossary of terms.
Name Directory
name-directory
Name directory (glossary) with many options like multiple directories, integrated search, non-latin characters, recaptcha, HTML editor and many more.
Glossary
glossary-by-codeat
Boost your SEO & UX with Codeat's Glossary: powerful auto-link engine; customizable tooltips, mobile settings, ChatGPT and much more!
Encyclopedia / Glossary / Wiki
encyclopedia-lexicon-glossary-wiki-dictionary
Supercharged tool to build your own awesome Encyclopedia / Lexicon / Glossary / Wiki / Dictionary / Knowledge base / Directory / Vocabulary in no time
Wordnik Word of the Day Widget Developer Profile
11 plugins · 11K total installs
How We Detect Wordnik Word of the Day Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
Wordnik Word of the Day