
Blog Time Security & Risk Analysis
wordpress.org/plugins/blog-timeDisplay the time according to your blog via an admin toolbar widget, a sidebar widget, and/or a template tag.
Is Blog Time Safe to Use in 2026?
Generally Safe
Score 85/100Blog Time has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The blog-time plugin v4.0.1 presents a mixed security posture. Its strengths lie in the absence of known CVEs and a commitment to using prepared statements for all SQL queries, indicating good database security practices. There are no critical or high-severity taint flows identified, and no file operations or external HTTP requests, which are common vectors for plugin compromise.
However, significant concerns arise from the static analysis. The plugin exposes two AJAX handlers, both of which lack authentication checks. This creates a substantial attack surface, as any unauthenticated user could potentially interact with these handlers. Furthermore, a notable portion of output (59%) is not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce checks on AJAX endpoints further exacerbates the risk of CSRF attacks against these unprotected entry points.
In conclusion, while the plugin avoids common pitfalls like unpatched vulnerabilities and raw SQL queries, the presence of unprotected AJAX handlers and insufficient output escaping represents a significant security risk. The lack of historical vulnerabilities is positive, but does not negate the immediate risks identified in the current version's code.
Key Concerns
- Unprotected AJAX handlers
- Insufficient output escaping
- Missing nonce checks on AJAX
Blog Time Security Vulnerabilities
Blog Time Release Timeline
Blog Time Code Analysis
Output Escaping
Blog Time Attack Surface
AJAX Handlers 2
WordPress Hooks 8
Maintenance & Trust
Blog Time Maintenance & Trust
Maintenance Signals
Community Trust
Blog Time Alternatives
Display Time(zone)
display-timezone
Display Timezone is simple plug-in to display current time with timezone in the upper right of your admin screen on every page.
Uptime, SEO and Security monitors – UptimeZone
uptime-seo-and-security-monitors-uptimezone
Downtime Happens. Get Notified! Uptime, SEO, and Vulnerability monitors for your website, totally free.
Countdown Timer Ultimate
countdown-timer-ultimate
A quick, easy way to add and display responsive Countdown timer on your website. Also work with Gutenberg shortcode block.
Date Time Field Add-On for Gravity Form
gf-datetime-field-add-on
A date-time add-on for Gravity Forms with custom date time format.
MX Time Zone Clocks
mx-time-zone-clocks
Add time zone clocks to your website.
Blog Time Developer Profile
63 plugins · 92K total installs
How We Detect Blog Time
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/blog-time/blog-time.css/wp-content/plugins/blog-time/blog-time.js/wp-content/plugins/blog-time/blog-time.jsblog-time/blog-time.css?ver=blog-time/blog-time.js?ver=HTML / DOM Fingerprints
blog-time-infoc2c_blog_time<!-- Blog Time -->id="c2c_blog_time"blog_time_params