
Hottaimoijiruna Security & Risk Analysis
wordpress.org/plugins/hottaimoijirunaHottaimoijiruna is a continuously updating AJAX powered clock for your site, with a customisable timezone so that you can display the time of day in y …
Is Hottaimoijiruna Safe to Use in 2026?
Generally Safe
Score 85/100Hottaimoijiruna has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hottaimoijiruna" v0.3 plugin exhibits a seemingly strong security posture on the surface due to a lack of identified attack surface entry points and dangerous functions. It also reports zero known vulnerabilities. However, a critical concern arises from the static analysis of its output handling. Despite having three total outputs, none of them are properly escaped. This indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into web pages displayed to users. Furthermore, the absence of nonce checks and capability checks suggests that even if an entry point were discovered, there are no built-in mechanisms to verify user permissions or prevent Cross-Site Request Forgery (CSRF) attacks. The zero taint analysis flows might be a result of the analysis scope or a lack of complex data manipulation within the plugin, but it doesn't negate the output escaping issues. In conclusion, while the plugin doesn't present immediate risks from known vulnerabilities or a large attack surface, the lack of output escaping is a critical weakness that needs immediate attention. The absence of nonce and capability checks are also notable weaknesses that increase the overall risk profile.
Key Concerns
- 0% output escaping
- 0 Nonce checks
- 0 Capability checks
Hottaimoijiruna Security Vulnerabilities
Hottaimoijiruna Code Analysis
Output Escaping
Hottaimoijiruna Attack Surface
Maintenance & Trust
Hottaimoijiruna Maintenance & Trust
Maintenance Signals
Community Trust
Hottaimoijiruna Alternatives
Countdown Timer Ultimate
countdown-timer-ultimate
A quick, easy way to add and display responsive Countdown timer on your website. Also work with Gutenberg shortcode block.
Blog Time
blog-time
Display the time according to your blog via an admin toolbar widget, a sidebar widget, and/or a template tag.
Shamsi, Gregorian, and Hijri Date and Time
shamsi-gregorian-and-hijri-date-and-time
This plugin displays the current time along with three calendar systems: Persian (Shamsi/Jalali), Islamic (Hijri), and Gregorian.
Date Time Picker for Contact Form 7
date-time-picker-for-contact-form-7
This plugin enables Contact Form 7 text field into a Date picker, Time picker or Date Time picker by using CSS class.
Meks Time Ago
meks-time-ago
Automatically change your post date display to "time ago" format like 1 hour ago, 3 days ago, etc...
Hottaimoijiruna Developer Profile
1 plugin · 10 total installs
How We Detect Hottaimoijiruna
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hottaimoijiruna/hottaimoijiruna.phpHTML / DOM Fingerprints
blink<!-- Hottaimoijiruna - AJAX powered clock for WordPress. --><!-- Copyright (c) 2005-2006 Jamie Talbot -->style="display: block; text-align: center;"hotta<span id="jikan" style="display: block; text-align: center;"></span>