
CoolClock – a Javascript Analog Clock Security & Risk Analysis
wordpress.org/plugins/coolclockShow an analog clock on your WordPress site sidebar or in post and page content.
Is CoolClock – a Javascript Analog Clock Safe to Use in 2026?
Generally Safe
Score 85/100CoolClock – a Javascript Analog Clock has a strong security track record. Known vulnerabilities have been patched promptly.
The "coolclock" plugin v4.3.7 exhibits a mixed security posture. While the static analysis reveals a small attack surface with no identified unprotected entry points and no dangerous functions or file operations, there are notable concerns regarding output escaping and a lack of comprehensive security checks. Specifically, 38% of output is not properly escaped, creating a potential for Cross-Site Scripting (XSS) vulnerabilities, which is corroborated by its vulnerability history. The absence of nonce checks and capability checks, particularly in the context of the shortcode, could allow for unintended execution if not properly handled by the WordPress core or other plugins.
Key Concerns
- Significant portion of output not properly escaped
- Missing nonce checks
- Missing capability checks
- Medium severity CVE in history
CoolClock – a Javascript Analog Clock Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CoolClock <= 4.3.4 - Authenticated Stored Cross-Site Scripting
CoolClock – a Javascript Analog Clock Code Analysis
Output Escaping
CoolClock – a Javascript Analog Clock Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
CoolClock – a Javascript Analog Clock Maintenance & Trust
Maintenance Signals
Community Trust
CoolClock – a Javascript Analog Clock Alternatives
Analog Clock Widget
analog-clock-widget
Analog Clock Widget plugin allows you to create an unlimited number of different analog clocks. The plugin based on SVG Raphael - JavaScript Library.
What Time Is It?
what-time-is-it
A lightweight plugin to display clock widgets on your website.
JS Categories List Widget
jquery-categories-list
A simple Gutenberg block and JS widget (can be called from posts) for displaying categories in a list with some effects.
Local Time Clock
local-time-clock
Display a clock on your sidebar set automatically to your location's timezone. Select from a choice of clocks, colors and sizes.
Digital Clock
digital-clock
The Digital Clock plugin adds a customizable sidebar clock that auto-adjusts to your timezone. Easy to use, it features dark and light themes.
CoolClock – a Javascript Analog Clock Developer Profile
8 plugins · 111K total installs
How We Detect CoolClock – a Javascript Analog Clock
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/coolclock/css/coolclock.css/wp-content/plugins/coolclock/js/coolclock.js/wp-content/plugins/coolclock/js/excanvas.min.js/wp-content/plugins/coolclock/js/coolclock.jscoolclock.js?ver=coolclock.css?ver=excanvas.min.js?ver=HTML / DOM Fingerprints
CoolClockcoolclock-subtext<!--[if lte IE 8]>class="CoolClock:CoolClock<canvas class="CoolClock:<div class="coolclock-subtext">