
Dynamic Time Security & Risk Analysis
wordpress.org/plugins/dynamic-timeThe number one timesheet plugin for WordPress. A simple calendar-based timecard and time management solution.
Is Dynamic Time Safe to Use in 2026?
Generally Safe
Score 100/100Dynamic Time has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'dynamic-time' plugin v5.4.23 exhibits a generally strong security posture. The absence of any known CVEs, combined with a significant number of capability checks and nonce checks, indicates a proactive approach to security by the developers. The plugin also demonstrates good practices by largely utilizing prepared statements for SQL queries and properly escaping a majority of its outputs. Furthermore, the lack of external HTTP requests minimizes risks associated with compromised external services.
However, a few areas warrant attention. The presence of two dangerous 'unserialize' functions, especially when coupled with one flow with an unsanitized path, presents a potential risk. If user-controlled data is allowed to reach these unserialize calls without proper sanitization, it could lead to serious vulnerabilities such as Remote Code Execution. While the taint analysis did not flag critical or high severity issues, this specific flow needs careful monitoring and validation of its sanitization. The plugin's total entry points are low, and importantly, none are unprotected, which is a significant strength.
In conclusion, 'dynamic-time' v5.4.23 is a reasonably secure plugin with good development practices. The primary concern lies with the 'unserialize' functions and the identified unsanitized flow, which, while not currently exploited or leading to critical issues in the analysis, represents a latent risk that should be addressed to further harden the plugin's security.
Key Concerns
- Dangerous unserialize function usage
- Flow with unsanitized path identified
- SQL queries using prepared statements (50%)
- Output escaping (68% properly escaped)
Dynamic Time Security Vulnerabilities
Dynamic Time Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Dynamic Time Attack Surface
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
Dynamic Time Maintenance & Trust
Maintenance Signals
Community Trust
Dynamic Time Alternatives
Time Tracker
time-tracker
Time Tracker enables freelancers to clients, projects, tasks (including recurring), time, billing info and more on private pages of their website.
UDSSL Time Tracker
udssl-time-tracker
UDSSL Time Tracker helps you to precisely track your time. Charts allows you to visualize how your time is spent and helps you to be more productive.
SD Timer – Live Time Tracker for Frontend & Backend
sd-timer
Best Time Tracker Plugin for WordPress websites. Make time management easier and simple.
User Activity Tracking and Log
user-activity-tracking-and-log
Track time and monitor user activity & history on your website, LMS online learning system, membership or WooCommerce site.
Simple Countdown Timer
simple-countdown
Simple Countdown Timer Plugin allows you to easily create and customize countdown timers for your website. Whether you're counting down to a sale …
Dynamic Time Developer Profile
8 plugins · 5K total installs
How We Detect Dynamic Time
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dynamic-time/assets/time_min.css/wp-content/plugins/dynamic-time/assets/time_min.js/wp-content/plugins/dynamic-time/assets/time_min.jsdynamic-time/assets/time_min.css?v=dynamic-time/assets/time_min.js?v=HTML / DOM Fingerprints
dyt_adminMenuCSSdata-dyt-idwindow.dyt_max_widthwindow.dyt_version[dyt_admin][dynamicTime]