
WP-RelativeDate Security & Risk Analysis
wordpress.org/plugins/wp-relativedateDisplays relative date alongside with your post/comments actual date.
Is WP-RelativeDate Safe to Use in 2026?
Generally Safe
Score 85/100WP-RelativeDate has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-relativedate plugin v1.51 demonstrates a generally good security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, file operations, and the consistent use of prepared statements for SQL queries are all positive indicators. Furthermore, the vulnerability history shows no recorded CVEs, suggesting a history of secure development or diligent patching by the authors.
However, there are some areas for concern. The lack of nonce checks and capability checks on the identified entry points (shortcodes) is a significant weakness. While the attack surface is small (only two shortcodes and no unprotected AJAX or REST API routes), any user-supplied input processed by these shortcodes could potentially be exploited without proper authorization or validation. The 89% output escaping rate, while high, still leaves a small window for potential cross-site scripting (XSS) vulnerabilities if the unescaped outputs are user-controlled.
In conclusion, the plugin exhibits strong fundamental security practices. The main risk lies in the potential for privilege escalation or unauthorized actions via the shortcodes due to the absence of nonce and capability checks. While the lack of past vulnerabilities is a positive sign, it doesn't negate the current identified risks. Addressing the missing authorization checks on the shortcodes would significantly improve the plugin's security.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Minor unescaped output detected
WP-RelativeDate Security Vulnerabilities
WP-RelativeDate Release Timeline
WP-RelativeDate Code Analysis
Output Escaping
WP-RelativeDate Attack Surface
Shortcodes 2
WordPress Hooks 5
Maintenance & Trust
WP-RelativeDate Maintenance & Trust
Maintenance Signals
Community Trust
WP-RelativeDate Alternatives
Days Ago Post Date
days-ago-post-date-format
Change post date format as human readable like 2mins ago, 2 days age, 1 year ago.
Meks Time Ago
meks-time-ago
Automatically change your post date display to "time ago" format like 1 hour ago, 3 days ago, etc...
Date counter
date-counter
Date counter - is just a 9 kilobytes WordPress plugin.
Today's Date Inserter
todays-date-inserter
Simply and quickly add the current date and or time to your wordpress posts or pages using a shortcode Date widget also included
On This Day (by Room 34)
room-34-presents-on-this-day
Display your blog posts from this date in previous years as a sidebar widget.
WP-RelativeDate Developer Profile
20 plugins · 888K total installs
How We Detect WP-RelativeDate
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
TodayYesterdayday agodays ago