Analog Clock Widget Security & Risk Analysis

wordpress.org/plugins/analog-clock-widget

Analog Clock Widget plugin allows you to create an unlimited number of different analog clocks. The plugin based on SVG Raphael - JavaScript Library.

100 active installs v1.3 PHP + WP 4.3+ Updated May 24, 2018
analog-clockclockclock-widgetcurrent-timetime
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Analog Clock Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Analog Clock Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "analog-clock-widget" plugin version 1.3 presents a mixed security profile. On the positive side, it demonstrates a clean vulnerability history with no known CVEs and no detected critical or high-severity issues in the static analysis. The absence of dangerous functions and external HTTP requests are also good indicators. Furthermore, all SQL queries utilize prepared statements, which is a robust security practice. However, there are significant concerns regarding output escaping, with only 8% of 142 outputs being properly escaped. This leaves a considerable risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the site's content. The plugin also performs file operations, and while the static analysis doesn't explicitly flag issues here, the lack of detailed information in this area warrants caution. The complete absence of nonce checks and capability checks on its (albeit zero) entry points, while currently not a direct risk due to the lack of entry points, means that if functionality were added in the future without proper security measures, it would be immediately vulnerable.

Key Concerns

  • Low percentage of properly escaped output
  • File operations present with no detailed analysis
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Analog Clock Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Analog Clock Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
130
12 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

8% escaped142 total outputs
Attack Surface

Analog Clock Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_enqueue_scriptsanalog-clock-widget.php:30
actionadmin_enqueue_scriptsanalog-clock-widget.php:31
actionwidgets_initanalog-clock-widget.php:294
Maintenance & Trust

Analog Clock Widget Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedMay 24, 2018
PHP min version
Downloads6K

Community Trust

Rating40/100
Number of ratings1
Active installs100
Developer Profile

Analog Clock Widget Developer Profile

mcnika

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Analog Clock Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/analog-clock-widget/js/raphael-min.js/wp-content/plugins/analog-clock-widget/js/analog-clock-widget.js
Script Paths
/wp-content/plugins/analog-clock-widget/js/raphael-min.js/wp-content/plugins/analog-clock-widget/js/analog-clock-widget.js

HTML / DOM Fingerprints

Data Attributes
id="u
JS Globals
draw_clock(
FAQ

Frequently Asked Questions about Analog Clock Widget