
WP Moon Phase Widget Security & Risk Analysis
wordpress.org/plugins/wp-moon-phase-widgetMoon phase widget for Wordpress
Is WP Moon Phase Widget Safe to Use in 2026?
Generally Safe
Score 85/100WP Moon Phase Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-moon-phase-widget" plugin v1.0.0 presents a generally positive security posture based on the static analysis. The absence of any detected dangerous functions, SQL injection vulnerabilities, or external HTTP requests is commendable. Furthermore, the plugin utilizes prepared statements for its SQL queries and appears to have a good level of output escaping, with 80% of detected outputs being properly escaped. The lack of any recorded vulnerabilities or CVEs in its history suggests a well-developed and maintained codebase.
However, a significant concern arises from the complete lack of capability checks and nonce checks. While the static analysis shows no direct entry points requiring authentication (AJAX, REST API, shortcodes, cron events), this doesn't guarantee future security if the plugin's functionality were to evolve. The complete absence of these security mechanisms, even with a seemingly small attack surface, represents a potential weakness that could be exploited if new features introduce such entry points without proper authorization checks. The lack of any taint analysis flows is also noted, though this might be due to the limited scope or complexity of the plugin's code.
In conclusion, the plugin demonstrates good coding practices in areas like SQL handling and output escaping, and its vulnerability-free history is a strong positive. Nevertheless, the complete omission of capability and nonce checks is a notable weakness. This indicates a potential blind spot in security implementation that, while not currently exploitable based on the provided data, could become a risk if the plugin is extended or modified in the future without addressing these fundamental security controls.
Key Concerns
- Missing capability checks
- Missing nonce checks
- 20% of outputs not properly escaped
WP Moon Phase Widget Security Vulnerabilities
WP Moon Phase Widget Code Analysis
Output Escaping
WP Moon Phase Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
WP Moon Phase Widget Maintenance & Trust
Maintenance Signals
Community Trust
WP Moon Phase Widget Alternatives
Moon Phases
moon-phases
Adds a sidebar widget that display the current moon phase.
Arianne G Esotools
arianne-g-esotools
A comprehensive esoteric tools plugin featuring numerology calculators, zodiac compatibility checker, and live moon phases display.
Support For Icomoon with Advanced Custom Fields
acf-icomoon
Add a field to select icons from a selection.json file generated by IcoMoon
PilotPress
pilotpress
PilotPress allows you to have a website, membership site, customer center, and a partner center integrated together with ONTRAPORT.
Astrology
astrology
Turn your Wordpress blog into a full astrology site, powered by Prokerala's astrology API.
WP Moon Phase Widget Developer Profile
1 plugin · 200 total installs
How We Detect WP Moon Phase Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-moon-phase-widget/js/automount.min.js/wp-content/plugins/wp-moon-phase-widget/js/automount.min.jsHTML / DOM Fingerprints
data-color<div id='moon-phase-widget'