
Clockinator Lite Security & Risk Analysis
wordpress.org/plugins/clockify-liteClockinator Lite is a powerful and easy-to-use employee and attendance management plugin for WordPress.
Is Clockinator Lite Safe to Use in 2026?
Mostly Safe
Score 79/100Clockinator Lite is generally safe to use. 1 past CVE were resolved.
The clockify-lite v1.0.8 plugin presents a mixed security posture. On the positive side, it demonstrates good practices in output escaping, with 96% of outputs properly escaped, and a high percentage (81%) of SQL queries utilizing prepared statements. It also shows a good number of nonce checks (41).
However, significant concerns arise from the extensive attack surface, particularly the 92 AJAX handlers that lack authentication checks. This represents a substantial risk, as any unauthenticated user could potentially trigger these handlers. The presence of 2 flows with unsanitized paths identified by taint analysis, even if rated as high severity rather than critical, indicates potential for injection vulnerabilities. The use of the `unserialize` function, a known vector for remote code execution if used with untrusted input, is also a concern.
The plugin's vulnerability history, with one medium severity CVE and a pattern of missing authorization, reinforces the concerns about its authentication and authorization mechanisms. While the last vulnerability was in the past, the nature of past issues (missing authorization) aligns with the static analysis findings of numerous unprotected AJAX handlers. Overall, while some good security practices are evident, the high number of unprotected AJAX endpoints, taint analysis findings, and historical vulnerability patterns create significant security risks that require immediate attention.
Key Concerns
- Numerous unprotected AJAX handlers
- Taint analysis: 2 high severity flows
- Vulnerability history: 1 medium unpatched CVE
- Dangerous function: unserialize
- Capability checks: 0
- Bundled library: DataTables (potential for known vulns if outdated)
Clockinator Lite Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Clockinator Lite <= 1.0.7 - Missing Authorization
Clockinator Lite Release Timeline
Clockinator Lite Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Clockinator Lite Attack Surface
AJAX Handlers 92
Shortcodes 10
WordPress Hooks 8
Maintenance & Trust
Clockinator Lite Maintenance & Trust
Maintenance Signals
Community Trust
Clockinator Lite Alternatives
HR Management Lite
hr-management-lite
HR Plugin for WordPress to Manage the HR works and the Projects.
Employee Management System
employee-management-system
A comprehensive employee management system with sales tracking, reporting, and dashboard features for WordPress.
School Management System – WPSchoolPress
wpschoolpress
An extensive plugin for school management with features like attendance, class management, time table, exams, grades, student-teacher-parent notificat …
VikAppointments Services Booking Calendar
vikappointments
A reliable tool for managing any kind of appointments, scheduling the bookings of various services, and organizing the calendars of several employees.
Clock In Portal- Staff & Attendance Management
clock-in-portal
Track the attendance of all registered employees with clock in or out system
Clockinator Lite Developer Profile
3 plugins · 180 total installs
How We Detect Clockinator Lite
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/clockify-lite/admin/css/clock-admin-notice.cssHTML / DOM Fingerprints
btcl-noticebtcl-notice__contentbtcl-notice__actionsbtcl-buttonBTCLite_PLUGIN_URLBTCLite_PLUGIN_DIR_PATHBTCLite_PLUGIN_BASENAMEBTCLite_PLUGIN_FILE