
WP Last Modified Info Security & Risk Analysis
wordpress.org/plugins/wp-last-modified-infoUltimate Last Modified Plugin for WordPress with Gutenberg support. Use shortcodes to show last modified info on WP 4.7+ sites.
Is WP Last Modified Info Safe to Use in 2026?
Generally Safe
Score 92/100WP Last Modified Info has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-last-modified-info" v1.9.6 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a relatively small attack surface with no identified unprotected entry points and a high percentage of properly escaped output. The absence of critical or high severity taint flows is also reassuring. However, the plugin's history of known vulnerabilities, particularly the prevalence of Missing Authorization, Cross-site Scripting, and Code Injection, raises significant concerns about its past security practices.
The static analysis does highlight some potential weaknesses. The presence of one SQL query that is not using prepared statements is a direct risk for SQL injection. While the specific flow is not detailed as unsanitized, it warrants attention. The plugin also performs one file operation and one external HTTP request, which could be vectors for further exploitation if not handled with extreme care and proper sanitization, although no unsanitized paths were found in the taint analysis.
Despite the absence of currently unpatched CVEs and a good output escaping rate, the plugin's historical pattern of security flaws suggests a need for ongoing vigilance. The types of past vulnerabilities indicate that input sanitization and authorization checks have been areas of weakness. Therefore, while the immediate findings are not dire, the plugin's track record demands a cautious approach. A strength is the presence of nonce and capability checks, indicating some attempt at securing functionalities.
Key Concerns
- SQL query not using prepared statements
- History of 5 known CVEs, including High severity
- Past vulnerabilities include Missing Authorization
- Past vulnerabilities include XSS and Code Injection
WP Last Modified Info Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
WP Last Modified Info <= 1.9.5 - Insecure Direct Object Reference to Authenticated (Author+) Post Metadata Modification
WP Last Modified Info <= 1.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Last Modified Info <= 1.9.4 - Authenticated (Contributor+) Remote Code Execution
WP Last Modified Info <= 1.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via lmt-post-modified-info Shortcode
WP Last Modified Info <= 1.6.5 - Stored Cross-Site Scripting
WP Last Modified Info Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Last Modified Info Attack Surface
Shortcodes 4
WordPress Hooks 10
Scheduled Events 1
Maintenance & Trust
WP Last Modified Info Maintenance & Trust
Maintenance Signals
Community Trust
WP Last Modified Info Alternatives
Freshtag – Last Modified Timestamp
freshtag
Display the “Last Modified” date on posts, pages, and products to signal freshness, boost SEO, and increase visitor trust
Last Modified Timestamp
last-modified-timestamp
Adds the last modified time to the admin interface as well as a [last-modified] shortcode to use on the front-end.
Post Updated Date
post-updated-date
Use Post Updated Date Plugin to display the Last Updated Date in WordPress Posts.
Show modified Date in admin lists
show-modified-date-in-admin-lists
Show modified date column in the lists of pages and posts in the WordPress admin panel.
WP Last Modified
wp-open-last-modified
This plugins adds the last modified date, current revision and the publication date of your post/page. Simply use the shortcode [last_modified_date]
WP Last Modified Info Developer Profile
5 plugins · 38K total installs
How We Detect WP Last Modified Info
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-last-modified-info/assets/css/admin.min.css/wp-content/plugins/wp-last-modified-info/assets/css/selectize.min.css/wp-content/plugins/wp-last-modified-info/assets/css/jquery-confirm.min.css/wp-content/plugins/wp-last-modified-info/assets/js/selectize.min.js/wp-content/plugins/wp-last-modified-info/assets/js/jquery-confirm.min.js/wp-content/plugins/wp-last-modified-info/assets/js/admin.min.js/wp-content/plugins/wp-last-modified-info/assets/js/admin.min.js/wp-content/plugins/wp-last-modified-info/assets/js/selectize.min.js/wp-content/plugins/wp-last-modified-info/assets/js/jquery-confirm.min.js/wp-content/plugins/wp-last-modified-info/assets/css/admin.min.css?ver=/wp-content/plugins/wp-last-modified-info/assets/js/admin.min.js?ver=/wp-content/plugins/wp-last-modified-info/assets/css/selectize.min.css?ver=0.15.2/wp-content/plugins/wp-last-modified-info/assets/css/jquery-confirm.min.css?ver=3.3.4/wp-content/plugins/wp-last-modified-info/assets/js/selectize.min.js?ver=0.15.2/wp-content/plugins/wp-last-modified-info/assets/js/jquery-confirm.min.js?ver=3.3.4HTML / DOM Fingerprints
wplmi-noticewplmi