
Countdown and CountUp, WooCommerce Sales Timer Security & Risk Analysis
wordpress.org/plugins/countdown-wpdevart-extendedWordPress Countdown and CountUp, WooCommerce Sales Timer plugin is a great tool. You can easily create countdown and countup timers for WordPress your …
Is Countdown and CountUp, WooCommerce Sales Timer Safe to Use in 2026?
Generally Safe
Score 99/100Countdown and CountUp, WooCommerce Sales Timer has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "countdown-wpdevart-extended" v1.9.0 plugin exhibits a mixed security posture. While it demonstrates good practices in output escaping (94% properly escaped) and a significant majority of its SQL queries use prepared statements (55%), several critical security concerns remain. The presence of two unprotected AJAX handlers significantly increases the attack surface, as these entry points could be exploited without proper authentication. Furthermore, the plugin has a history of known vulnerabilities, including a high-severity cross-site scripting (XSS) and a medium-severity cross-site request forgery (CSRF) vulnerability, the latter being relatively recent. Although there are no currently unpatched CVEs, this history suggests a pattern of potential security weaknesses that require diligent attention.
Key Concerns
- Unprotected AJAX handlers found
- History of high and medium severity CVEs
- SQL queries not using prepared statements
- Flows with unsanitized paths found
Countdown and CountUp, WooCommerce Sales Timer Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Countdown and CountUp, WooCommerce Sales Timer <= 1.8.2 - Authenticated (Administrator+) Stored Cross-Site Scripting via plugin settings
Countdown and CountUp, WooCommerce Sales Timers <= 1.5.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Countdown and CountUp, WooCommerce Sales Timer Release Timeline
Countdown and CountUp, WooCommerce Sales Timer Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Countdown and CountUp, WooCommerce Sales Timer Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
Countdown and CountUp, WooCommerce Sales Timer Maintenance & Trust
Maintenance Signals
Community Trust
Countdown and CountUp, WooCommerce Sales Timer Alternatives
Sales Countdown Timer
sales-countdown-timer
Create versatile countdown timers for your WordPress site and WooCommerce products, including progress bars and upcoming sale countdowns.
Finale Lite – Sales Countdown Timer & Discount for WooCommerce
finale-woocommerce-sales-countdown-timer-discount
Finale lets you create scheduled one time or recurring campaigns. It induces urgency with visual elements such as Countdown Timer and Counter Bar to m …
Met Sales Countdown- All‑in‑one FOMO plugin for WooCommerce
sales-countdown-discount-timer
Met Sales Countdown to increase sales and create urgency for buying your products.
Countdown Timer – Widget Countdown
widget-countdown
Countdown timer plugin is an nice tool to create and insert timers into your posts/pages and widgets.
Delivery Countdown Timer
delivery-countdown-timer
Show the nextday delivery timer with text based on cut off time.
Countdown and CountUp, WooCommerce Sales Timer Developer Profile
45 plugins · 52K total installs
How We Detect Countdown and CountUp, WooCommerce Sales Timer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/countdown-wpdevart-extended/includes/admin/css/font-awesome.min.css/wp-content/plugins/countdown-wpdevart-extended/includes/admin/gutenberg/style.css/wp-content/plugins/countdown-wpdevart-extended/includes/admin/css/jquery-ui-style.css/wp-content/plugins/countdown-wpdevart-extended/includes/frontend/js/popup.js/wp-content/plugins/countdown-wpdevart-extended/includes/admin/js/date-time-picker/jquery-ui-timepicker-addon.css/wp-content/plugins/countdown-wpdevart-extended/includes/admin/js/date-time-picker/jquery-ui-timepicker-addon.js/wp-content/plugins/countdown-wpdevart-extended/includes/admin/gutenberg/block.jswpdevart_countdown_extended_popup_frontjquery-ui-date-time-picker-jswpda_countdown_extended_gutenberg_jsHTML / DOM Fingerprints
wpda_countdown_extended_widget