
Current Date & Time Widget Security & Risk Analysis
wordpress.org/plugins/current-date-time-widgetProvides a widget that shows the current date and time given a specified timezone and format.
Is Current Date & Time Widget Safe to Use in 2026?
Generally Safe
Score 85/100Current Date & Time Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'current-date-time-widget' plugin version 1.0.3 exhibits a strong security posture from a static analysis perspective, with no identified attack surface points such as AJAX handlers, REST API routes, or shortcodes. The absence of dangerous functions and file operations further contributes to its security. The fact that all SQL queries utilize prepared statements is a significant positive indicator, demonstrating adherence to secure database practices. However, a major concern arises from the complete lack of output escaping, with 0% of the 7 identified output points being properly escaped. This presents a significant risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected and executed within the user's browser.
The plugin's vulnerability history is clean, with no recorded CVEs. This, combined with the lack of critical or high-severity taint flows, suggests a generally secure codebase. However, the lack of nonce and capability checks, while not directly tied to a vulnerability in this version, represents a missed opportunity to implement robust access control and prevent potential future exploits, especially if new entry points were to be introduced or discovered. The overall security is good due to the lack of direct vulnerabilities and clean history, but the unescaped output is a critical flaw that needs immediate attention.
Key Concerns
- Unescaped output
- Missing nonce checks
- Missing capability checks
Current Date & Time Widget Security Vulnerabilities
Current Date & Time Widget Code Analysis
Output Escaping
Current Date & Time Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
Current Date & Time Widget Maintenance & Trust
Maintenance Signals
Community Trust
Current Date & Time Widget Alternatives
WP Server Date Time
wp-server-date-time
This plugin shows the server local current date time & timezone in the upper right of your admin screen on every page.
WP User Timezone
wp-user-timezone
WP User Timezone displays the front-end dates & times in the browser's local timezone without actually modifying your database.
Date Time Picker for Contact Form 7
date-time-picker-for-contact-form-7
This plugin enables Contact Form 7 text field into a Date picker, Time picker or Date Time picker by using CSS class.
Countdown Timer Ultimate
countdown-timer-ultimate
A quick, easy way to add and display responsive Countdown timer on your website. Also work with Gutenberg shortcode block.
Meks Time Ago
meks-time-ago
Automatically change your post date display to "time ago" format like 1 hour ago, 3 days ago, etc...
Current Date & Time Widget Developer Profile
4 plugins · 71K total installs
How We Detect Current Date & Time Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
widefatid="current-date-time"<p id="current-date-time">