
Clock In Portal- Staff & Attendance Management Security & Risk Analysis
wordpress.org/plugins/clock-in-portalTrack the attendance of all registered employees with clock in or out system
Is Clock In Portal- Staff & Attendance Management Safe to Use in 2026?
High Risk
Score 48/100Clock In Portal- Staff & Attendance Management carries significant security risk with 3 known CVEs, 3 still unpatched. Consider switching to a maintained alternative.
The clock-in-portal v2.4 plugin exhibits a mixed security posture. While it demonstrates good practices in its use of prepared statements for SQL queries and proper output escaping, significant concerns arise from its attack surface and taint analysis. The presence of two unprotected AJAX handlers is a major vulnerability, creating direct entry points for attackers. Furthermore, the taint analysis revealing two high-severity flows with unsanitized paths indicates potential for data manipulation or execution of unintended code. The plugin's vulnerability history is also a notable weakness, with three unpatched medium-severity CVEs, all identified as Cross-Site Request Forgery (CSRF) vulnerabilities. This pattern suggests a recurring issue with input validation and authorization, potentially leaving users exposed to malicious actions performed on their behalf. While the plugin's code quality in other areas is commendable, the unprotected entry points and identified high-severity taint flows, coupled with a history of CSRF vulnerabilities, elevate the overall risk.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- Unpatched CVEs (3 medium)
- Use of dangerous function (unserialize)
- Low capability checks (1 total)
Clock In Portal- Staff & Attendance Management Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Clock In Portal <= 2.1 - Cross-Site Request Forgery To Staff Deletion
Clock In Portal <= 2.1 - Cross-Site Request Forgery to Holidays Deletion
Clock In Portal <= 2.1 - Cross-Site Request Forgery to Designation Deletion
Clock In Portal- Staff & Attendance Management Release Timeline
Clock In Portal- Staff & Attendance Management Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Clock In Portal- Staff & Attendance Management Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
Clock In Portal- Staff & Attendance Management Maintenance & Trust
Maintenance Signals
Community Trust
Clock In Portal- Staff & Attendance Management Alternatives
HR Management Lite
hr-management-lite
HR Plugin for WordPress to Manage the HR works and the Projects.
Clockinator Lite
clockify-lite
Clockinator Lite is a powerful and easy-to-use employee and attendance management plugin for WordPress.
Blog2Social: Social Media Auto Post & Scheduler
blog2social
Automatically share and schedule your WordPress content on top social platforms like Facebook, Instagram, LinkedIn, TikTok, and more.
Action Scheduler
action-scheduler
Action Scheduler - Job Queue for WordPress
SchedulePress – Auto Post & Publish, Auto Social Share, Schedule Posts with Editorial Calendar & Missed Schedule Post Publisher
wp-scheduled-posts
Automate your WordPress content scheduling with a visual calendar, auto/manual schedulers, missed‑post handler, social sharing options & templates.
Clock In Portal- Staff & Attendance Management Developer Profile
23 plugins · 6K total installs
How We Detect Clock In Portal- Staff & Attendance Management
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clock-in-portal/js/bootstrap.min.js/wp-content/plugins/clock-in-portal/js/flipclock.js/wp-content/plugins/clock-in-portal/js/jquery-date-format.js/wp-content/plugins/clock-in-portal/js/moment.js/wp-content/plugins/clock-in-portal/js/bootstrap-datetimepicker.js/wp-content/plugins/clock-in-portal/css/style.cssclock-in-portal/js/bootstrap.min.js?ver=clock-in-portal/js/flipclock.js?ver=clock-in-portal/js/jquery-date-format.js?ver=clock-in-portal/js/moment.js?ver=clock-in-portal/js/bootstrap-datetimepicker.js?ver=clock-in-portal/css/style.css?ver=HTML / DOM Fingerprints
update-pluginscount-1plugin-countCIP_PLG_URL