HRM Work Tracking Security & Risk Analysis
wordpress.org/plugins/hrm-work-trackingHRM Work Tracking plugin is a complete employee or user time tracking in the WordPress backend.
Is HRM Work Tracking Safe to Use in 2026?
Generally Safe
Score 85/100HRM Work Tracking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hrm-work-tracking" v1.5 plugin exhibits a mixed security posture. On the positive side, it has a very small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all detected SQL queries utilize prepared statements, and there are no file operations or external HTTP requests. The presence of nonce and capability checks is also a good indicator of security awareness.
However, a significant concern arises from the output escaping. With 81 total outputs and only 4% properly escaped, there is a high probability of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis further highlights this by revealing 4 flows with unsanitized paths, though thankfully none were classified as critical or high severity. This suggests that while data might be reaching potentially vulnerable output points, the actual risk of exploitation might be mitigated by other factors or the nature of the data itself. The lack of any recorded vulnerability history is a strong positive, suggesting a history of secure development, but it does not negate the immediate risks identified in the static analysis.
In conclusion, while the plugin demonstrates good practices in areas like SQL handling and attack surface reduction, the extremely low rate of proper output escaping is a critical weakness. The taint analysis supports the concern that unsanitized data is flowing to potentially insecure output locations. The absence of past vulnerabilities is encouraging, but the current static analysis indicates a need for urgent attention to output sanitization to mitigate potential XSS risks.
Key Concerns
- Low output escaping rate (4%)
- Flows with unsanitized paths (4)
HRM Work Tracking Security Vulnerabilities
HRM Work Tracking Code Analysis
Output Escaping
Data Flow Analysis
HRM Work Tracking Attack Surface
WordPress Hooks 31
Maintenance & Trust
HRM Work Tracking Maintenance & Trust
Maintenance Signals
Community Trust
HRM Work Tracking Alternatives
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier
aio-time-clock-lite
Employees can easily clock in and out. Managers can run reports, keep track of employees/volunteers/contractors and their time.
Time Clock – A WordPress Employee & Volunteer Time Clock Plugin
time-clock
An employee / volunteer time clock for WordPress
Post Worktime Logger
post-worktime-logger
Post Worktime Logger is a WordPress plugin that allows you to track the time you worked on each post.
Plain Tracker
plaintracker
A time clock plugin to track and analyze time of employees, workers or volunteers.
Countdown Timer Ultimate
countdown-timer-ultimate
A quick, easy way to add and display responsive Countdown timer on your website. Also work with Gutenberg shortcode block.
HRM Work Tracking Developer Profile
11 plugins · 220 total installs
How We Detect HRM Work Tracking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hrm-work-tracking/style.csshrm-work-tracking/style.css?ver=hrm-work-tracking/hrm-script.js?ver=HTML / DOM Fingerprints
hrm-dashboard-wrap<!-- since 1.1 --><!-- for 1.5 --><!-- deprecated in 1.1 --><!-- since 1.42 -->data-hrm-user-iddata-hrm-noncehrm_user_idhrm_nonce