CountDown FlipClock Security & Risk Analysis

wordpress.org/plugins/countdown-flipclock

Welcome to the page of the next-gen 3D countdown timer - CountDown FlipClock, created and maintained by BlueLevel Communications.

80 active installs v2.7.3 PHP + WP 3.7.1+ Updated Jul 19, 2018
clockcountdowncountdown-clockcountdown-timertimer
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CountDown FlipClock Safe to Use in 2026?

Generally Safe

Score 85/100

CountDown FlipClock has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "countdown-flipclock" plugin v2.7.3 demonstrates a generally good security posture based on the provided static analysis and vulnerability history. The plugin has no known CVEs, indicating a history of security diligence or a lack of exploitable vulnerabilities discovered. The static analysis reveals a minimal attack surface, with only one shortcode identified and no unprotected entry points. Furthermore, the code adheres to secure coding practices by utilizing prepared statements for all SQL queries, implementing nonce and capability checks, and avoiding dangerous functions or file operations.

However, there is a notable concern regarding output escaping, with only 69% of outputs being properly escaped. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is involved in the unescaped outputs. While no critical or high-severity taint flows were detected, the lack of full output escaping remains a weakness that could be exploited. The plugin's reliance on a bundled library, TinyMCE, could also pose a risk if that library itself has known vulnerabilities that are not being addressed by the plugin author.

In conclusion, the plugin is relatively secure due to its limited attack surface and adherence to core security practices. The absence of past vulnerabilities is a positive sign. The primary area for improvement and a potential risk lies in the incomplete output escaping, which warrants attention. The bundled library should also be monitored for potential security issues.

Key Concerns

  • Outputs not properly escaped
  • Bundled library (TinyMCE)
Vulnerabilities
None known

CountDown FlipClock Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

CountDown FlipClock Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
20 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

69% escaped29 total outputs
Attack Surface

CountDown FlipClock Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[FlipClock] FlipIncludes\FlipShortcode.php:109
WordPress Hooks 12
actioninitFlipIncludes\FlipCustomPost.php:29
actionwp_enqueue_scriptsFlipIncludes\FlipFiles.php:14
actionadmin_footerFlipIncludes\FlipFiles.php:35
actionadd_meta_boxesFlipIncludes\FlipMetaboxes.php:13
actionadd_meta_boxesFlipIncludes\FlipMetaboxes.php:37
actionadd_meta_boxesFlipIncludes\FlipMetaboxes.php:158
actionadd_meta_boxesFlipIncludes\FlipMetaboxes.php:174
actionsave_postFlipIncludes\FlipMetaboxes.php:223
actionadmin_noticesFlipIncludes\FlipMisc.php:23
filtermce_external_pluginsFlipTinymce\FlipTinyMCE.php:8
filtermce_buttonsFlipTinymce\FlipTinyMCE.php:9
actionadmin_headFlipTinymce\FlipTinyMCE.php:11
Maintenance & Trust

CountDown FlipClock Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJul 19, 2018
PHP min version
Downloads10K

Community Trust

Rating70/100
Number of ratings4
Active installs80
Developer Profile

CountDown FlipClock Developer Profile

BlueLevel

2 plugins · 90 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CountDown FlipClock

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/countdown-flipclock/FlipCss/flipclock.css/wp-content/plugins/countdown-flipclock/FlipJs/flipclock.min.js/wp-content/plugins/countdown-flipclock/FlipCss/jquery.timepicker.min.css/wp-content/plugins/countdown-flipclock/FlipCss/datepicker.css/wp-content/plugins/countdown-flipclock/FlipCss/jquery-ui.css/wp-content/plugins/countdown-flipclock/FlipJs/jquery.timepicker.min.js/wp-content/plugins/countdown-flipclock/FlipJs/custom.js
Script Paths
/wp-content/plugins/countdown-flipclock/FlipJs/flipclock.min.js/wp-content/plugins/countdown-flipclock/FlipJs/jquery.timepicker.min.js/wp-content/plugins/countdown-flipclock/FlipJs/custom.js
Version Parameters
countdown-flipclock/flipclock.css?ver=countdown-flipclock/flipclock.min.js?ver=countdown-flipclock/jquery.timepicker.min.css?ver=countdown-flipclock/datepicker.css?ver=countdown-flipclock/jquery-ui.css?ver=countdown-flipclock/jquery.timepicker.min.js?ver=countdown-flipclock/custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
flip-clock-wrapperflip-clock-dividerflip-clock-labeldayshoursminutessecondstwoDayDigits+2 more
Data Attributes
data-cdfc
JS Globals
FlipClock
Shortcode Output
<div class="clock<script type="text/javascript">var futureDate = new Date(var currentDate = new Date();
FAQ

Frequently Asked Questions about CountDown FlipClock