
Clock Tik Tik Security & Risk Analysis
wordpress.org/plugins/clock-tik-tikWith this plugin you can now easily customize WooCommerce My Account Page and add custom options related to your Pages.
Is Clock Tik Tik Safe to Use in 2026?
Generally Safe
Score 85/100Clock Tik Tik has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The clock-tik-tik plugin version 1.0 demonstrates a strong security posture based on the provided static analysis. It follows best practices by utilizing prepared statements for all SQL queries and properly escaping all output, indicating no immediate vulnerabilities related to data injection or cross-site scripting. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security profile. Furthermore, the plugin has no recorded vulnerability history, suggesting a commitment to security or a lack of past exploitations.
However, there are a few areas that warrant attention. The plugin relies on only two capability checks for its entry points, which could be a concern if these capabilities are overly broad. The presence of two shortcodes as entry points, while not directly flagged as insecure in this analysis, represents potential attack vectors that should be carefully managed. The lack of nonce checks on its entry points, though currently it has no unprotected AJAX handlers or REST API routes, could become a weakness if new handlers are added without proper security.
Overall, clock-tik-tik v1.0 appears to be a relatively secure plugin, with a clean code analysis and no known vulnerabilities. The primary recommendations would be to ensure the capability checks are as granular as possible and to maintain vigilance regarding the security of its shortcode implementations. Future development should prioritize implementing nonce checks if any AJAX or REST API functionalities are introduced.
Key Concerns
- Limited capability checks on entry points
- Potential attack surface with shortcodes
- Missing nonce checks on entry points
Clock Tik Tik Security Vulnerabilities
Clock Tik Tik Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Clock Tik Tik Attack Surface
Shortcodes 2
WordPress Hooks 2
Maintenance & Trust
Clock Tik Tik Maintenance & Trust
Maintenance Signals
Community Trust
Clock Tik Tik Alternatives
IP2Location World Clock
ip2location-world-clock
Simple world clock widget to display analog or digital clock for multiple time zone on your site. Supported local time, visitor's time and custom …
Simple Digital Clock 🕒
simple-digital-clock
It is 🪄 a magical and easy-to-use digital clock with a beautiful UI, supporting multiple languages, locales, dates, captions, and time zones.
Universal Clocks
universal-clocks
Elegant and easy to use plugin to add a wide range of clocks on your website!
What Time Is It?
what-time-is-it
A lightweight plugin to display clock widgets on your website.
World Clock Dropdown with ShortCodes
world-clock-with-drop-down-shortcodes
A shortcode plugin to display timezone dropdown with digital clock(local time), with hours, minutes & seconds.
Clock Tik Tik Developer Profile
5 plugins · 130 total installs
How We Detect Clock Tik Tik
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clock-tik-tik/assets/css/global.css/wp-content/plugins/clock-tik-tik/assets/css/select2.min.css/wp-content/plugins/clock-tik-tik/assets/css/fontawesome.all.css/wp-content/plugins/clock-tik-tik/assets/js/sweetalert.min.js/wp-content/plugins/clock-tik-tik/assets/js/select2.min.js/wp-content/plugins/clock-tik-tik/assets/js/ajax_main.js/wp-content/plugins/clock-tik-tik/assets/js/sweetalert.min.js/wp-content/plugins/clock-tik-tik/assets/js/select2.min.js/wp-content/plugins/clock-tik-tik/assets/js/ajax_main.jsHTML / DOM Fingerprints
clock_dedital_tikDClockclockkid='clock_digital_main'ajax_scripthours_mint_second_[tik_analog_clock][tik_digital_clock]