
Countdown, Coming Soon, Maintenance – Countdown & Clock Security & Risk Analysis
wordpress.org/plugins/countdown-builderCountdown builder - Customizable Countdown Timer
Is Countdown, Coming Soon, Maintenance – Countdown & Clock Safe to Use in 2026?
Use With Caution
Score 65/100Countdown, Coming Soon, Maintenance – Countdown & Clock has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "countdown-builder" plugin v3.0.8 exhibits a mixed security posture. On the positive side, the static analysis shows excellent adherence to secure coding practices, with all identified SQL queries utilizing prepared statements, a very high percentage of output escaping, and robust nonce and capability checks on its entry points. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. However, the vulnerability history is a significant concern. With 10 known CVEs, including one that is currently unpatched, and common vulnerability types such as Path Traversal, Code Injection, and Cross-Site Scripting, this plugin has a history of introducing serious security flaws. The presence of an unpatched CVE, even if not specified by severity in the provided data, suggests a direct and immediate risk to users running this version. While the current static analysis indicates improvements, the historical patterns strongly advise caution.
Key Concerns
- Unpatched CVE detected
- History of high severity vulnerabilities (2 high CVEs)
- History of medium severity vulnerabilities (7 medium CVEs)
- History of low severity vulnerabilities (1 low CVE)
- Taint analysis shows unsanitized paths
- Bundled library Select2 potentially outdated
- Bundled library TinyMCE potentially outdated
Countdown, Coming Soon, Maintenance – Countdown & Clock Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.8.9.1 - Unauthenticated Limited Local File Inclusion
Countdown & Clock <= 2.8.8 - Authenticated (Contributor+) Remote Code Execution
Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.9.3 - Authenticated (Admin+) Stored Cross-Site Scripting
Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.7.8 - Missing Authorization to Authenticated (Subscriber+) PHP Object Injection
Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.3.9.5 - Authenticated Cross-Site Scripting
Countdown & Clock <= 2.3.2 - Pro Features Lock Bypass
Countdown, Coming Soon, Maintenance – Countdown & Clock <= 2.3.2 - Cross-Site Scripting
Countdown & Clock <= 2.3.2 - Reflected Cross-Site Scripting
Countdown & Clock <= 2.3.2 - Authenticated (Admin+) Stored Cross-Site Scripting
Countdown & Clock <= 2.2.8 - Reflected Cross-Site Scripting
Countdown, Coming Soon, Maintenance – Countdown & Clock Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Countdown, Coming Soon, Maintenance – Countdown & Clock Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 74
Maintenance & Trust
Countdown, Coming Soon, Maintenance – Countdown & Clock Maintenance & Trust
Maintenance Signals
Community Trust
Countdown, Coming Soon, Maintenance – Countdown & Clock Alternatives
Countdown Timer Ultimate
countdown-timer-ultimate
A quick, easy way to add and display responsive Countdown timer on your website. Also work with Gutenberg shortcode block.
HurryTimer – An Scarcity and Urgency Countdown Timer for WordPress & WooCommerce
hurrytimer
Create unlimited urgency and scarcity countdown timers for WordPress and WooCommerce to boost conversions and sales instantly.
Countdown Timer – Widget Countdown
widget-countdown
Countdown timer plugin is an nice tool to create and insert timers into your posts/pages and widgets.
Coming Soon & Maintenance Mode by Colorlib
colorlib-coming-soon-maintenance
Create a coming soon page or maintenance mode screen with 15 responsive templates, countdown timer, MailChimp subscribe form, and social media links.
HashBar – Announcement, Notification Bar & Popup Campaign
hashbar-wp-notification-bar
Create Announcement Bars, Notification Bars & Popup Campaigns with countdown timers, A/B testing, smart targeting & analytics.
Countdown, Coming Soon, Maintenance – Countdown & Clock Developer Profile
2 plugins · 10K total installs
How We Detect Countdown, Coming Soon, Maintenance – Countdown & Clock
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/countdown-builder/assets/css/admin/admin-style.css/wp-content/plugins/countdown-builder/assets/css/admin/ycd-tinymce-plugin.css/wp-content/plugins/countdown-builder/assets/css/cd-styles.css/wp-content/plugins/countdown-builder/assets/css/cd-responsive.css/wp-content/plugins/countdown-builder/assets/css/cd-custom-styles.css/wp-content/plugins/countdown-builder/assets/js/admin/ycd-tinymce-plugin.js/wp-content/plugins/countdown-builder/assets/js/admin/countdown-builder-admin.js/wp-content/plugins/countdown-builder/assets/js/jquery.countdown.min.js+1 more/wp-content/plugins/countdown-builder/assets/js/admin/ycd-tinymce-plugin.jscountdown-builder/assets/css/admin/admin-style.css?ver=countdown-builder/assets/css/admin/ycd-tinymce-plugin.css?ver=countdown-builder/assets/css/cd-styles.css?ver=countdown-builder/assets/css/cd-responsive.css?ver=countdown-builder/assets/css/cd-custom-styles.css?ver=countdown-builder/assets/js/admin/ycd-tinymce-plugin.js?ver=countdown-builder/assets/js/admin/countdown-builder-admin.js?ver=countdown-builder/assets/js/jquery.countdown.min.js?ver=countdown-builder/assets/js/countdown-builder.js?ver=HTML / DOM Fingerprints
ycd-countdown-builderycd-countdown-contentycd-countdown-wrapperycd-countdown-elementycd-countdown-item<!-- If this file is called directly, abort. --><!-- Start: YCD Countdown Builder --><!-- End: YCD Countdown Builder --><!-- Countdown Builder Admin Options -->+1 moredata-plugin-name="countdown-builder"data-plugin-version="3.0.8"YCD_COUNTDOWN_POST_TYPEYCD_TEXT_DOMAINYCD_COUNTDOWN_PRO_URLYCD_FREE_VERSIONYCD_PKG_VERSIONtickbox+1 more[ycd_countdown