ClockPms Security & Risk Analysis

wordpress.org/plugins/clocksky

Use ClockPms plugin to embed our Web Reservation System in to your wordpress site.

10 active installs v1.1 PHP + WP 3.0.1+ Updated Jun 12, 2014
booking-systemclock-pmsclockskycloud-based-property-management-systeminternet-reservation-system
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ClockPms Safe to Use in 2026?

Generally Safe

Score 85/100

ClockPms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the 'clocksky' plugin v1.1 exhibits an exceptionally strong security posture. The code analysis reveals no dangerous functions, no raw SQL queries, all output is properly escaped, and there are no file operations or external HTTP requests. Crucially, there are no detected taint flows, indicating that user-supplied data is not being processed in a way that could lead to vulnerabilities like code injection or path traversal. The complete absence of known CVEs further reinforces this positive assessment.

While the plugin demonstrates excellent internal security practices, the analysis does highlight a potential concern: the lack of any identified capability checks or nonce checks. This, combined with the presence of one shortcode and zero unprotected entry points, suggests that while the current implementation may be safe, there's a foundational lack of explicit security controls. If future versions introduce new functionalities or if the shortcode were to become exposed to user input in an unforeseen way, this lack of built-in checks could become a weakness. However, as it stands, with zero unprotected entry points and no historical vulnerabilities, the plugin appears to be very secure.

Key Concerns

  • No capability checks identified
  • No nonce checks identified
Vulnerabilities
None known

ClockPms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ClockPms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

ClockPms Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[clockpms] clocksky.php:29
Maintenance & Trust

ClockPms Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedJun 12, 2014
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

ClockPms Developer Profile

clock-software

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ClockPms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/clocksky/js/iframe_integration.js

HTML / DOM Fingerprints

JS Globals
clock_pms_iframe
Shortcode Output
<script src='https://sky-eu1.clock-software.com/js/iframe_integration.js'></script>
FAQ

Frequently Asked Questions about ClockPms