
Display Time(zone) Security & Risk Analysis
wordpress.org/plugins/display-timezoneDisplay Timezone is simple plug-in to display current time with timezone in the upper right of your admin screen on every page.
Is Display Time(zone) Safe to Use in 2026?
Generally Safe
Score 85/100Display Time(zone) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "display-timezone" plugin version 1.0.6 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code analysis indicates no dangerous functions are used, all SQL queries are properly prepared, and there are no identified file operations or external HTTP requests, which are excellent security practices.
However, a critical concern arises from the output escaping analysis. With 3 total outputs and 0% properly escaped, this indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data that is displayed without proper sanitization could be exploited by attackers to inject malicious scripts into web pages. The lack of explicit capability and nonce checks across the plugin's entry points, while the attack surface is currently zero, means that if any entry points were to be added in the future, they would likely be unprotected.
The plugin has no recorded vulnerability history, which is a positive indicator. This suggests that the developers have historically maintained a secure codebase or that the plugin is not a target for attackers. However, the absence of vulnerabilities does not negate the risks identified in the static analysis, particularly the critical lack of output escaping. The overall security is good due to the minimal attack surface and good coding practices in SQL and function usage, but the unescaped output represents a clear and present danger.
Key Concerns
- All outputs are unescaped
- Missing capability checks
- Missing nonce checks
Display Time(zone) Security Vulnerabilities
Display Time(zone) Code Analysis
Output Escaping
Display Time(zone) Attack Surface
WordPress Hooks 3
Maintenance & Trust
Display Time(zone) Maintenance & Trust
Maintenance Signals
Community Trust
Display Time(zone) Alternatives
Countdown Timer Ultimate
countdown-timer-ultimate
A quick, easy way to add and display responsive Countdown timer on your website. Also work with Gutenberg shortcode block.
WPC Countdown Timer for WooCommerce
wpc-countdown-timer
WPC Countdown Timer helps you display countdown timer in single product pages and shop page.
WP Flipclock
wp-flipclock
Quickly and easily add a flipclock to your site’s posts and pages via a shortcode.
EZ Countdown Timer
ez-countdown-timer
A customizable countdown timer plugin for WordPress that allows you to create multiple timers with custom styling and live preview.
World Clock
flash-world-clock
World clock showing the local time at six major cities round the world. The plugin provides a choice of analog and digital clocks, colors and sizes.
Display Time(zone) Developer Profile
2 plugins · 20 total installs
How We Detect Display Time(zone)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/display-timezone/js/Date.format.js/wp-content/plugins/display-timezone/js/Date.format.jsHTML / DOM Fingerprints
tboy_displayTimezoneSpanid="tboy_displayTimezoneSpan"id="tboy_displayTimezone"tboy_setTimezonetboy_getTimezone