WP Last Modified Info Security & Risk Analysis

wordpress.org/plugins/wp-last-modified-info

Ultimate Last Modified Plugin for WordPress with Gutenberg support. Use shortcodes to show last modified info on WP 4.7+ sites.

30K active installs v1.9.6 PHP 7.0+ WP 4.7+ Updated Jan 30, 2026
last-modifiedmodified-timepost-modifiedsort-by-modifiedtimestamp
92
A · Safe
CVEs total5
Unpatched0
Last CVEFeb 13, 2026
Safety Verdict

Is WP Last Modified Info Safe to Use in 2026?

Generally Safe

Score 92/100

WP Last Modified Info has a strong security track record. Known vulnerabilities have been patched promptly.

5 known CVEsLast CVE: Feb 13, 2026Updated 2mo ago
Risk Assessment

The "wp-last-modified-info" v1.9.6 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a relatively small attack surface with no identified unprotected entry points and a high percentage of properly escaped output. The absence of critical or high severity taint flows is also reassuring. However, the plugin's history of known vulnerabilities, particularly the prevalence of Missing Authorization, Cross-site Scripting, and Code Injection, raises significant concerns about its past security practices.

The static analysis does highlight some potential weaknesses. The presence of one SQL query that is not using prepared statements is a direct risk for SQL injection. While the specific flow is not detailed as unsanitized, it warrants attention. The plugin also performs one file operation and one external HTTP request, which could be vectors for further exploitation if not handled with extreme care and proper sanitization, although no unsanitized paths were found in the taint analysis.

Despite the absence of currently unpatched CVEs and a good output escaping rate, the plugin's historical pattern of security flaws suggests a need for ongoing vigilance. The types of past vulnerabilities indicate that input sanitization and authorization checks have been areas of weakness. Therefore, while the immediate findings are not dire, the plugin's track record demands a cautious approach. A strength is the presence of nonce and capability checks, indicating some attempt at securing functionalities.

Key Concerns

  • SQL query not using prepared statements
  • History of 5 known CVEs, including High severity
  • Past vulnerabilities include Missing Authorization
  • Past vulnerabilities include XSS and Code Injection
Vulnerabilities
5

WP Last Modified Info Security Vulnerabilities

CVEs by Year

1 CVE in 2020
2020
1 CVE in 2024
2024
2 CVEs in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

High
1
Medium
4

5 total CVEs

CVE-2025-14608medium · 5.3Missing Authorization

WP Last Modified Info <= 1.9.5 - Insecure Direct Object Reference to Authenticated (Author+) Post Metadata Modification

Feb 13, 2026 Patched in 1.9.6 (1d)
CVE-2025-62968medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Last Modified Info <= 1.9.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 18, 2025 Patched in 1.9.3 (24d)
CVE-2025-52756high · 8.8Improper Control of Generation of Code ('Code Injection')

WP Last Modified Info <= 1.9.4 - Authenticated (Contributor+) Remote Code Execution

Aug 24, 2025 Patched in 1.9.5 (81d)
CVE-2024-6864medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Last Modified Info <= 1.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via lmt-post-modified-info Shortcode

Aug 19, 2024 Patched in 1.9.1 (1d)
WF-9694c8b6-3e2f-499f-bdac-eed78d89e08a-wp-last-modified-infomedium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Last Modified Info <= 1.6.5 - Stored Cross-Site Scripting

Apr 3, 2020 Patched in 1.6.6 (1390d)
Code Analysis
Analyzed Mar 16, 2026

WP Last Modified Info Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
16
217 escaped
Nonce Checks
5
Capability Checks
13
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

93% escaped233 total outputs
Data Flows
All sanitized

Data Flow Analysis

6 flows
dismiss_notice (inc\Base\AdminNotice.php:107)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Last Modified Info Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[lmt-post-modified-info] inc\Core\Frontend\Shortcode.php:26
[lmt-page-modified-info] inc\Core\Frontend\Shortcode.php:27
[lmt-template-tags] inc\Core\Frontend\Shortcode.php:28
[lmt-site-modified-info] inc\Core\Frontend\Shortcode.php:29
WordPress Hooks 10
filteraioseo_last_modified_date_disableinc\Core\Backend\BlockEditor.php:146
filteraioseo_limit_modified_date_post_typesinc\Core\Backend\BlockEditor.php:147
filterthe_dateinc\Core\Backend\MiscActions.php:168
filterthe_timeinc\Core\Backend\MiscActions.php:169
filterthe_modified_dateinc\Core\Backend\MiscActions.php:170
filterget_the_dateinc\Core\Backend\MiscActions.php:171
filterget_the_timeinc\Core\Backend\MiscActions.php:172
filterget_the_modified_dateinc\Core\Backend\MiscActions.php:173
actionadmin_initwp-last-modified-info.php:141
actionadmin_noticeswp-last-modified-info.php:142

Scheduled Events 1

wplmi/fetch_plugin_data
Maintenance & Trust

WP Last Modified Info Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 30, 2026
PHP min version7.0
Downloads679K

Community Trust

Rating98/100
Number of ratings827
Active installs30K
Developer Profile

WP Last Modified Info Developer Profile

Sayan Datta

5 plugins · 38K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
218 days
View full developer profile
Detection Fingerprints

How We Detect WP Last Modified Info

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-last-modified-info/assets/css/admin.min.css/wp-content/plugins/wp-last-modified-info/assets/css/selectize.min.css/wp-content/plugins/wp-last-modified-info/assets/css/jquery-confirm.min.css/wp-content/plugins/wp-last-modified-info/assets/js/selectize.min.js/wp-content/plugins/wp-last-modified-info/assets/js/jquery-confirm.min.js/wp-content/plugins/wp-last-modified-info/assets/js/admin.min.js
Script Paths
/wp-content/plugins/wp-last-modified-info/assets/js/admin.min.js/wp-content/plugins/wp-last-modified-info/assets/js/selectize.min.js/wp-content/plugins/wp-last-modified-info/assets/js/jquery-confirm.min.js
Version Parameters
/wp-content/plugins/wp-last-modified-info/assets/css/admin.min.css?ver=/wp-content/plugins/wp-last-modified-info/assets/js/admin.min.js?ver=/wp-content/plugins/wp-last-modified-info/assets/css/selectize.min.css?ver=0.15.2/wp-content/plugins/wp-last-modified-info/assets/css/jquery-confirm.min.css?ver=3.3.4/wp-content/plugins/wp-last-modified-info/assets/js/selectize.min.js?ver=0.15.2/wp-content/plugins/wp-last-modified-info/assets/js/jquery-confirm.min.js?ver=3.3.4

HTML / DOM Fingerprints

CSS Classes
wplmi-notice
JS Globals
wplmi
FAQ

Frequently Asked Questions about WP Last Modified Info