Connections Business Directory Local Time Security & Risk Analysis

wordpress.org/plugins/connections-business-directory-local-time

An extension for Connections Business Directory which adds the ability to show the local time of a business or an individual based on their address.

80 active installs v1.2.1 PHP 5.6.20+ WP 5.1+ Updated Apr 13, 2024
business-directoryclocklocal-time
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Connections Business Directory Local Time Safe to Use in 2026?

Generally Safe

Score 92/100

Connections Business Directory Local Time has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

This plugin, "connections-business-directory-local-time" v1.2.1, exhibits a generally strong security posture based on the provided static analysis. It boasts a minimal attack surface with only one AJAX handler, and crucially, no unprotected entry points into the application. The code signals indicate good development practices, with all SQL queries using prepared statements and a single nonce check and capability check present. File operations and external HTTP requests are absent, further reducing potential attack vectors. The lack of critical or high-severity taint flows is also a positive indicator. However, a notable concern is the moderate rate of output escaping, with only 58% of outputs being properly escaped. This suggests a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully in the remaining unescaped outputs. The absence of any recorded vulnerabilities in its history is commendable, but this should not lead to complacency, especially given the output escaping issue.

In conclusion, while the plugin demonstrates a strong foundation in securing its core functionalities and entry points, the output escaping weakness is a specific area that requires attention. This suggests that while direct exploitation through major flaws like SQL injection or unauthenticated RCE is unlikely based on this analysis, an attacker might still find ways to inject malicious scripts through improperly sanitized output. The plugin's clean vulnerability history is a positive sign, but the observed code quality signal in output escaping warrants careful consideration.

Key Concerns

  • Moderate rate of unescaped output
Vulnerabilities
None known

Connections Business Directory Local Time Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Connections Business Directory Local Time Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
7 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

58% escaped12 total outputs
Attack Surface

Connections Business Directory Local Time Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_save-widgetconnections-local-time.php:127
WordPress Hooks 7
actionwidgets_initconnections-local-time.php:120
actioncn_clean_entry_cacheconnections-local-time.php:123
actioncn_clean_term_cacheconnections-local-time.php:124
actionwp_enqueue_scriptsconnections-local-time.php:130
actionwp_enqueue_scriptsconnections-local-time.php:131
actionadmin_noticesconnections-local-time.php:258
actionplugins_loadedconnections-local-time.php:273
Maintenance & Trust

Connections Business Directory Local Time Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 13, 2024
PHP min version5.6.20
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs80
Developer Profile

Connections Business Directory Local Time Developer Profile

Steven

14 plugins · 1K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Connections Business Directory Local Time

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/connections-business-directory-local-time/includes/vendor/jClocksGMT/css/jClocksGMT.css/wp-content/plugins/connections-business-directory-local-time/includes/vendor/jClocksGMT/js/jquery.rotate.js/wp-content/plugins/connections-business-directory-local-time/includes/vendor/jClocksGMT/js/jClocksGMT.js
Version Parameters
connections-business-directory-local-time/includes/vendor/jClocksGMT/css/jClocksGMT.css?ver=connections-business-directory-local-time/includes/vendor/jClocksGMT/js/jquery.rotate.js?ver=connections-business-directory-local-time/includes/vendor/jClocksGMT/js/jClocksGMT.js?ver=

HTML / DOM Fingerprints

CSS Classes
jclockgmt
Data Attributes
data-plugin-name="Connections Business Directory Extension - Local Time"data-plugin-version="1.2.1"
JS Globals
jQuery(document).ready( function(){ jQuery('jQuery.fn.jClocksGMT = function(options) {
Shortcode Output
<div id="cn-clock-jQuery(document).ready( function(){ jQuery("#cn-clock-").jClocksGMT(
FAQ

Frequently Asked Questions about Connections Business Directory Local Time