Devgirl Countdown Clock Security & Risk Analysis

wordpress.org/plugins/devgirl-countdown-clock

A simple countdown timer/clock you can place in a page, post or widget using a shortcode. Elementor-friendly.

10 active installs v2.0 PHP 5.2+ WP 4.9+ Updated Mar 16, 2023
countdown-clockcountdown-timerevent-launchestime-limit
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Devgirl Countdown Clock Safe to Use in 2026?

Generally Safe

Score 85/100

Devgirl Countdown Clock has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The devgirl-countdown-clock plugin v2.0 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are all positive indicators. The plugin also shows a high percentage of properly escaped output and uses capability checks, suggesting an awareness of secure coding practices. The vulnerability history being completely clear further strengthens this impression, indicating a track record of security attention or a lack of past exploitable issues.

However, a critical concern arises from the complete absence of nonce checks and the limited attack surface analysis. While there are no unprotected AJAX handlers or REST API routes listed, the presence of a shortcode with no explicitly mentioned authorization or input sanitization could potentially be an entry point. The taint analysis shows zero flows, which is ideal, but this could also be due to the limited scope of the analysis or the nature of the plugin's functionality. The plugin relies on a single capability check, which might not be sufficient if the shortcode handles sensitive operations or user-submitted data.

Overall, the plugin is relatively secure with no known critical or high-severity vulnerabilities and good coding practices in place. The main area for improvement lies in ensuring robust authorization and input validation for its shortcode functionality, even if no specific issues were flagged by the static analysis. The lack of nonce checks, while not directly exploitable given the current analysis, represents a missed opportunity for enhanced security.

Key Concerns

  • No nonce checks on entry points
  • Limited capability checks on shortcode
Vulnerabilities
None known

Devgirl Countdown Clock Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Devgirl Countdown Clock Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
24 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped28 total outputs
Attack Surface

Devgirl Countdown Clock Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[devgirl-countdown-clock] devgirl-countdown-clock.php:116
WordPress Hooks 4
actionwp_enqueue_scriptsdevgirl-countdown-clock.php:131
actionadmin_enqueue_scriptsdevgirl-countdown-clock.php:139
actioninitdevgirl-countdown-clock.php:148
actionadmin_menuincludes\admin-menu.php:18
Maintenance & Trust

Devgirl Countdown Clock Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedMar 16, 2023
PHP min version5.2
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Devgirl Countdown Clock Developer Profile

devgirl

3 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Devgirl Countdown Clock

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/devgirl-countdown-clock/style/countdown-clock-frontend.css/wp-content/plugins/devgirl-countdown-clock/script/countdown-clock.js/wp-content/plugins/devgirl-countdown-clock/style/countdown-clock-backend.css
Script Paths
/wp-content/plugins/devgirl-countdown-clock/script/countdown-clock.js
Version Parameters
devgirl-countdown-clock/style/countdown-clock-frontend.css?ver=devgirl-countdown-clock/script/countdown-clock.js?ver=devgirl-countdown-clock/style/countdown-clock-backend.css?ver=

HTML / DOM Fingerprints

CSS Classes
devgirl-countdown-clockdays-clock-valuehours-clock-valuemins-clock-valuesecs-clock-valuebox
Data Attributes
data-namedata-timedata-clock-colourdata-text-colourdata-style
JS Globals
DevgirlCountdownClock
Shortcode Output
<div class="devgirl-countdown-clock<div class="box"<script type="text/javascript">new DevgirlCountdownClock
FAQ

Frequently Asked Questions about Devgirl Countdown Clock