Clock Tik Tik Security & Risk Analysis

wordpress.org/plugins/clock-tik-tik

With this plugin you can now easily customize WooCommerce My Account Page and add custom options related to your Pages.

0 active installs v1.0 PHP 7.0+ WP 5.5+ Updated May 26, 2022
analog-clockclockdigital-clockworld-clock
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Clock Tik Tik Safe to Use in 2026?

Generally Safe

Score 85/100

Clock Tik Tik has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The clock-tik-tik plugin version 1.0 demonstrates a strong security posture based on the provided static analysis. It follows best practices by utilizing prepared statements for all SQL queries and properly escaping all output, indicating no immediate vulnerabilities related to data injection or cross-site scripting. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security profile. Furthermore, the plugin has no recorded vulnerability history, suggesting a commitment to security or a lack of past exploitations.

However, there are a few areas that warrant attention. The plugin relies on only two capability checks for its entry points, which could be a concern if these capabilities are overly broad. The presence of two shortcodes as entry points, while not directly flagged as insecure in this analysis, represents potential attack vectors that should be carefully managed. The lack of nonce checks on its entry points, though currently it has no unprotected AJAX handlers or REST API routes, could become a weakness if new handlers are added without proper security.

Overall, clock-tik-tik v1.0 appears to be a relatively secure plugin, with a clean code analysis and no known vulnerabilities. The primary recommendations would be to ensure the capability checks are as granular as possible and to maintain vigilance regarding the security of its shortcode implementations. Future development should prioritize implementing nonce checks if any AJAX or REST API functionalities are introduced.

Key Concerns

  • Limited capability checks on entry points
  • Potential attack surface with shortcodes
  • Missing nonce checks on entry points
Vulnerabilities
None known

Clock Tik Tik Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Clock Tik Tik Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
317 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

100% escaped317 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<add_new_clock_template> (templates\add_new_clock_template.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Clock Tik Tik Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[tik_analog_clock] inc\clockFunctions.php:11
[tik_digital_clock] inc\clockFunctions.php:12
WordPress Hooks 2
actionadmin_menuinc\clock_setting.php:12
actionadmin_enqueue_scriptsinc\clock_setting.php:14
Maintenance & Trust

Clock Tik Tik Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedMay 26, 2022
PHP min version7.0
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Clock Tik Tik Developer Profile

charlestsmith

5 plugins · 130 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Clock Tik Tik

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/clock-tik-tik/assets/css/global.css/wp-content/plugins/clock-tik-tik/assets/css/select2.min.css/wp-content/plugins/clock-tik-tik/assets/css/fontawesome.all.css/wp-content/plugins/clock-tik-tik/assets/js/sweetalert.min.js/wp-content/plugins/clock-tik-tik/assets/js/select2.min.js/wp-content/plugins/clock-tik-tik/assets/js/ajax_main.js
Script Paths
/wp-content/plugins/clock-tik-tik/assets/js/sweetalert.min.js/wp-content/plugins/clock-tik-tik/assets/js/select2.min.js/wp-content/plugins/clock-tik-tik/assets/js/ajax_main.js

HTML / DOM Fingerprints

CSS Classes
clock_dedital_tikDClockclockk
Data Attributes
id='clock_digital_main'
JS Globals
ajax_scripthours_mint_second_
Shortcode Output
[tik_analog_clock][tik_digital_clock]
FAQ

Frequently Asked Questions about Clock Tik Tik