
WP Sessions Time Monitoring Full Automatic Security & Risk Analysis
wordpress.org/plugins/activitytimePlugin will accurately measure all activity time per page and user like working time, reading time, watching time, sessions time for specific user on …
Is WP Sessions Time Monitoring Full Automatic Safe to Use in 2026?
Generally Safe
Score 87/100WP Sessions Time Monitoring Full Automatic has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'activitytime' plugin exhibits a concerning security posture due to a significant number of unprotected entry points and a history of critical vulnerabilities. While the plugin utilizes prepared statements for all SQL queries, which is a strong security practice, this is overshadowed by the presence of 5 unprotected entry points (AJAX handlers and REST API routes). Furthermore, the static analysis reveals 6 high-severity taint flows with unsanitized paths, indicating a real risk of sensitive data exposure or manipulation. The 'unserialize' function also poses a potential risk if not handled with extreme care.
The plugin's vulnerability history is also a major red flag, with 3 known CVEs including a past critical vulnerability. The common types of vulnerabilities (XSS and SQL Injection) align with the identified taint flows and unprotected entry points, suggesting persistent weaknesses in input validation and sanitization. The absence of nonce checks on AJAX handlers and only one capability check across all entry points further exacerbates these risks, making it easier for attackers to exploit.
In conclusion, despite the good practice of using prepared statements for SQL, the 'activitytime' plugin has significant security weaknesses. The high number of unprotected entry points, the critical taint flows, and the historical vulnerability record point to a plugin that requires immediate attention and remediation to mitigate potential exploitation.
Key Concerns
- Unprotected AJAX handlers
- Unprotected REST API routes
- High severity taint flows
- Unsanitized paths in taint flows
- Dangerous unserialize function
- No nonce checks
- Low capability check coverage
- Bundled outdated Freemius v1.0
- Past critical vulnerability
- Past high severity vulnerability
- Past medium severity vulnerability
WP Sessions Time Monitoring Full Automatic Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
WP Sessions Time Monitoring Full Automatic <= 1.1.4 - Authenticated (Subscriber+) SQL Injection
Sessions Time Monitoring Full Automatic <= 1.1.3 - Missing Authorization
WP Sessions Time Monitoring Full Automatic <= 1.1.1 - Reflected Cross-Site Scripting
WP Sessions Time Monitoring Full Automatic <= 1.0.9 - Unauthenticated SQL Injection
WP Sessions Time Monitoring Full Automatic <= 1.0.8 - Unauthenticated SQL injection
WP Sessions Time Monitoring Full Automatic Release Timeline
WP Sessions Time Monitoring Full Automatic Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Sessions Time Monitoring Full Automatic Attack Surface
AJAX Handlers 3
REST API Routes 2
Shortcodes 1
WordPress Hooks 17
Maintenance & Trust
WP Sessions Time Monitoring Full Automatic Maintenance & Trust
Maintenance Signals
Community Trust
WP Sessions Time Monitoring Full Automatic Alternatives
Health Monitor
health-monitor
Health Monitor is designed to help you keep your website running smoothly. It continuously checks your site’s performance, security, and overall healt …
Incident Agent
incident-agent
Complete WordPress monitoring with real-time alerts, error tracking, and uptime monitoring. Know about issues before your users do.
User Activity Tracking and Log
user-activity-tracking-and-log
Track time and monitor user activity & history on your website, LMS online learning system, membership or WooCommerce site.
Simple Countdown Timer
simple-countdown
Simple Countdown Timer Plugin allows you to easily create and customize countdown timers for your website. Whether you're counting down to a sale …
Shipday Local Delivery for WooCommerce
shipday-for-woocommerce
Shipday adds local delivery and pickup workflows, dispatch sync, and checkout date/time selection to WooCommerce.
WP Sessions Time Monitoring Full Automatic Developer Profile
5 plugins · 1K total installs
How We Detect WP Sessions Time Monitoring Full Automatic
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/activitytime/admin/css/activitytime-admin.css/wp-content/plugins/activitytime/public/css/activitytime-public.css/wp-content/plugins/activitytime/public/js/activitytime-public.js/wp-content/plugins/activitytime/public/js/activitytime-public.jsactivitytime-admin.css?ver=activitytime-public.css?ver=activitytime-public.js?ver=HTML / DOM Fingerprints
activitytime-admin-wrapactivity-time-widgetactt-progress-baractt-widget-rowactivity-time-table-wrapactivitytime-content-wrapper<!-- Activitytime Admin Setting --><!-- Activitytime Admin Setting END --><!-- Activity time widget --><!-- Activity time widget END -->+4 moredata-activitytime-post-iddata-activitytime-user-iddata-activitytime-post-typeactivitytime_dataactivitytime_admin_params[activity_time_chart][activity_time_table]