
Verse Of The Day Security & Risk Analysis
wordpress.org/plugins/wp-votdDisplays a daily bible verse on your site, using a Verse of the Day RSS feed.
Is Verse Of The Day Safe to Use in 2026?
Generally Safe
Score 85/100Verse Of The Day has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-votd v3.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of direct entry points like AJAX handlers, REST API routes, and shortcodes, combined with no identified dangerous functions, file operations, or external HTTP requests, suggests a limited attack surface. Furthermore, all SQL queries are reported to use prepared statements, which is a critical security best practice. The lack of any recorded vulnerabilities or CVEs in its history is also a positive indicator of its security maturity.
However, a significant concern arises from the output escaping analysis. With 7 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any data rendered by the plugin without proper sanitization and escaping could be exploited by attackers to inject malicious scripts. The absence of nonce and capability checks, while not directly tied to a tangible attack vector in the static analysis, implies that actions might not be adequately protected against CSRF or unauthorized access, especially if new entry points are introduced or internal functions are called directly. This combination of unescaped output presents the most immediate and critical risk.
In conclusion, while wp-votd v3.0 demonstrates good practices in areas like SQL handling and limiting its attack surface, the critical deficiency in output escaping severely undermines its overall security. The vulnerability history is reassuring, but it cannot compensate for the immediate XSS risk. Addressing the output escaping is paramount to improving its security. The lack of explicit authorization checks on the single cron event also warrants investigation.
Key Concerns
- 0% output escaping
- 0 Nonce checks
- 0 Capability checks
- 1 Cron event without apparent auth check
Verse Of The Day Security Vulnerabilities
Verse Of The Day Release Timeline
Verse Of The Day Code Analysis
Output Escaping
Verse Of The Day Attack Surface
WordPress Hooks 2
Scheduled Events 1
Maintenance & Trust
Verse Of The Day Maintenance & Trust
Maintenance Signals
Community Trust
Verse Of The Day Alternatives
Bible Verses References
bible-verses-references
This plugin fetches all the biblical references present in your posts and pages and adds the text of the verse in a floating window when the user hove …
DAILY CHRISTIAN BIBLE VERSES
daily-christian-bible-verses
DAILY CHRISTIAN BIBLE VERSES
PrimeBible Verse Preview
primebible
Automatically detects Bible references and displays beautiful verse previews on hover or tap. Mobile-optimized, fast, and fully customizable.
Logos Reftagger
reftagger
Logos Reftagger turns Bible references into links to the verse on Biblia.com and adds tooltips with the text of the verse.
Bible Verse of the Day
bible-verse-of-the-day
Shows the daily inspiring Bible verse or a random Bible verse from DailyVerses.net. In English, Spanish, Portuguese, German, French, Italian, Polish, …
Verse Of The Day Developer Profile
6 plugins · 80 total installs
How We Detect Verse Of The Day
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
votd-contentid="votd"<p id="votd">[TEXT] (<a href="[LINK]">[TITLE]</a>[VERSION])[ENCLOSURE]</p>