
wp date range Security & Risk Analysis
wordpress.org/plugins/wp-date-rangeDate range for Posts or Custom types
Is wp date range Safe to Use in 2026?
Generally Safe
Score 85/100wp date range has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-date-range" plugin v1.2 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is commendable. Furthermore, the presence of nonce checks and the exclusive use of prepared statements for its single SQL query indicate good development practices for preventing common web vulnerabilities. The plugin's limited attack surface with no direct entry points like AJAX handlers, REST API routes, or shortcodes further contributes to its secure design.
However, a significant concern arises from the taint analysis, which revealed one flow with an unsanitized path. While this flow did not escalate to a critical or high severity, it still represents a potential avenue for exploitation, particularly if the plugin handles user-supplied data in its path processing. The relatively low percentage of properly escaped output (18%) is another area of concern. This could lead to Cross-Site Scripting (XSS) vulnerabilities if user-controlled data is ever displayed without adequate sanitization or escaping.
The plugin's vulnerability history is entirely clean, with no recorded CVEs. This is a positive indicator and suggests that past versions have likely been developed with security in mind or have not been targets of significant attacks. In conclusion, "wp-date-range" v1.2 demonstrates strengths in its minimal attack surface and robust SQL handling, but the presence of an unsanitized path and insufficient output escaping warrant careful consideration and potential remediation.
Key Concerns
- Flow with unsanitized path detected
- Low percentage of properly escaped output
wp date range Security Vulnerabilities
wp date range Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
wp date range Attack Surface
WordPress Hooks 12
Maintenance & Trust
wp date range Maintenance & Trust
Maintenance Signals
Community Trust
wp date range Alternatives
Availability Datepicker – Booking Calendar for Contact Form 7 – Input WP
date-time-picker-field
Availability datepicker & booking calendar for any form. Configure business hours, time slots, date overrides and a booking window.
Date Price Calendar for WooCommerce
date-price-calendar
It displays a jQuery popup calendar as product option on the front-end product page.
Simple Calendar DatePicker
simple-calendar-picker
This plugin allows you to set datepicker,calendar on your posts and pages just in single click.
WP-Persian
wp-persian
Fast and Powerful plugin for Jalali calendar and Farsi language support in Wordpress and standard plugins.
WP Datepicker
wp-datepicker
A great plugin to implement custom styled jQuery UI datepicker site-wide.
wp date range Developer Profile
1 plugin · 10 total installs
How We Detect wp date range
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-date-range/css/smoothness/jquery-ui-1.8.11.custom.css/wp-content/plugins/wp-date-range/css/wp-daterange.css/wp-content/plugins/wp-date-range/js/jquery-ui-i18n.min.custom.js/wp-content/plugins/wp-date-range/js/admin.jsHTML / DOM Fingerprints
date_range_settingswp_date_range optiondata-date-formatdata-date-separatordata-date-languagedata-date-posttypeswp_date_range_vars