
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier Security & Risk Analysis
wordpress.org/plugins/aio-time-clock-liteEmployees can easily clock in and out. Managers can run reports, keep track of employees/volunteers/contractors and their time.
Is All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier Safe to Use in 2026?
Generally Safe
Score 95/100All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier has a strong security track record. Known vulnerabilities have been patched promptly.
The "aio-time-clock-lite" v2.0.4 plugin presents a mixed security posture. While it demonstrates good practices by exclusively using prepared statements for SQL queries and performing a reasonable number of capability checks, significant concerns remain regarding its attack surface and vulnerability history. The presence of two AJAX handlers without authentication checks is a primary weakness, creating potential entry points for unauthorized actions. Taint analysis indicates unsanitized paths, which, although not flagged as critical or high severity in this scan, could potentially lead to vulnerabilities if exploited in conjunction with other weaknesses.
The plugin's vulnerability history, with 5 known medium-severity CVEs, including common types like Missing Authorization, Authorization Bypass, Cross-Site Scripting (XSS), and Cross-Site Request Forgery (CSRF), is a significant red flag. The fact that all previously disclosed vulnerabilities are patched suggests a commitment to addressing security issues. However, the sheer number and variety of past vulnerabilities indicate a pattern of insecure coding practices that require ongoing vigilance. The most recent vulnerability was disclosed in late 2025, which is a concern for a plugin version that may be older.
In conclusion, the plugin has strengths in its SQL handling and some security checks. However, the unprotected AJAX endpoints, potential taint flow issues, and a history of multiple medium-severity vulnerabilities across various types necessitate careful consideration. Users should prioritize ensuring the plugin is up-to-date and be aware of the potential risks associated with the exposed AJAX endpoints, even if no critical issues were found in the current static analysis.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Total known CVEs (5 medium)
- Low percentage of properly escaped output
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier <= 2.0.3 - Missing Authorization to Page Creation and Information Exposure
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier <= 2.0 - Insecure Direct Object Reference to Authenticated (Subscriber+) Arbitrary Clocking In/Out
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier <= 2.0 - Reflected Cross-Site Scripting
All in One Time Clock Lite <= 1.3.325 - Cross-Site Request Forgery
All in One Time Clok Lite <= 1.3.320 - Authenticated (Admin+) Stored Cross-Site Scripting
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 31
Maintenance & Trust
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier Maintenance & Trust
Maintenance Signals
Community Trust
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier Alternatives
Time Clock – A WordPress Employee & Volunteer Time Clock Plugin
time-clock
An employee / volunteer time clock for WordPress
Plain Tracker
plaintracker
A time clock plugin to track and analyze time of employees, workers or volunteers.
HRM Work Tracking
hrm-work-tracking
HRM Work Tracking plugin is a complete employee or user time tracking in the WordPress backend.
Countdown Timer Ultimate
countdown-timer-ultimate
A quick, easy way to add and display responsive Countdown timer on your website. Also work with Gutenberg shortcode block.
MX Time Zone Clocks
mx-time-zone-clocks
Add time zone clocks to your website.
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier Developer Profile
1 plugin · 700 total installs
How We Detect All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aio-time-clock-lite/aio-time-clock-lite.js/wp-content/plugins/aio-time-clock-lite/aio-time-clock-lite.css/wp-content/plugins/aio-time-clock-lite/aio-time-clock-lite-admin.js/wp-content/plugins/aio-time-clock-lite/aio-time-clock-lite-admin.css/wp-content/plugins/aio-time-clock-lite/assets/css/aio-time-clock-lite-front.css/wp-content/plugins/aio-time-clock-lite/assets/js/aio-time-clock-lite-front.js/wp-content/plugins/aio-time-clock-lite/assets/js/aio-time-clock-lite-admin.js/wp-content/plugins/aio-time-clock-lite/assets/css/aio-time-clock-lite-admin.css/wp-content/plugins/aio-time-clock-lite/aio-time-clock-lite.js/wp-content/plugins/aio-time-clock-lite/aio-time-clock-lite-admin.js/wp-content/plugins/aio-time-clock-lite/assets/js/aio-time-clock-lite-front.js/wp-content/plugins/aio-time-clock-lite/assets/js/aio-time-clock-lite-admin.jsaio-time-clock-lite/aio-time-clock-lite.js?ver=aio-time-clock-lite/aio-time-clock-lite.css?ver=aio-time-clock-lite/aio-time-clock-lite-admin.js?ver=aio-time-clock-lite/aio-time-clock-lite-admin.css?ver=aio-time-clock-lite/assets/css/aio-time-clock-lite-front.css?ver=aio-time-clock-lite/assets/js/aio-time-clock-lite-front.js?ver=aio-time-clock-lite/assets/js/aio-time-clock-lite-admin.js?ver=aio-time-clock-lite/assets/css/aio-time-clock-lite-admin.css?ver=HTML / DOM Fingerprints
aio-tc-lite-clockinaio-tc-lite-clockoutaio-tc-lite-time-displayaio-tc-lite-reports-tableaio_timeclock_lite_admin_menuaio_timeclock_lite_settings_pageaio_timeclock_lite_monitoring_pageaio_timeclock_lite_employees_page+2 more<!-- Start of AIO Time Clock Lite Shortcode --><!-- End of AIO Time Clock Lite Shortcode --><!-- AIO Time Clock Lite Admin Settings --><!-- AIO Time Clock Lite Monitoring -->+2 moredata-aio-tc-lite-actiondata-aio-tc-lite-noncedata-aio-tc-lite-user-iddata-aio-tc-lite-roleaio_time_clock_lite_ajax_objectaio_time_clock_lite_admin_ajax_objectaio_time_clock_lite_vars/wp-json/aio-time-clock-lite/v1/clock-in/wp-json/aio-time-clock-lite/v1/clock-out/wp-json/aio-time-clock-lite/v1/get-time-entries/wp-json/aio-time-clock-lite/v1/get-employee-data/wp-json/aio-time-clock-lite/v1/save-settings[show_aio_time_clock_lite][show_aio_employee_profile_lite]