IMS Countdown Security & Risk Analysis

wordpress.org/plugins/ims-countdown

IMS Countdown timer allows you to display a countdown on your post or page.

100 active installs v1.4.1 PHP + WP 3.0.1+ Updated Nov 25, 2025
commentsspam
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 13, 2024
Safety Verdict

Is IMS Countdown Safe to Use in 2026?

Generally Safe

Score 99/100

IMS Countdown has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 13, 2024Updated 4mo ago
Risk Assessment

The ims-countdown plugin v1.4.1 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are all positive indicators. The high percentage of properly escaped output and the presence of nonce and capability checks further contribute to a secure foundation. The attack surface is minimal and appears to be well-protected.

However, the plugin's vulnerability history is a significant concern. The presence of one known medium-severity CVE, specifically Cross-Site Scripting (XSS), dated very recently (2024-12-13), suggests that while the current version might not be unpatched, past vulnerabilities have existed and may indicate a recurring pattern or areas where the development team has struggled with secure coding practices. The fact that this vulnerability is not currently marked as patched could imply that the v1.4.1 itself is affected or that patching is still in progress, which is a critical observation.

In conclusion, while the static analysis of v1.4.1 shows good development practices in many areas, the past XSS vulnerability and its recent date necessitates caution. The plugin has strengths in its limited attack surface and use of security features, but the historical vulnerability data points to a potential area of weakness that requires careful monitoring and confirmation of patching status.

Key Concerns

  • Recently patched medium severity XSS vulnerability
Vulnerabilities
1

IMS Countdown Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-11755medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

IMS Countdown <= 1.3.5 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 13, 2024 Patched in 1.3.6 (330d)
Code Analysis
Analyzed Mar 16, 2026

IMS Countdown Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
78 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped79 total outputs
Attack Surface

IMS Countdown Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[displayCountdowns] includes\class-ims-countdown.php:181
WordPress Hooks 10
actionplugins_loadedincludes\class-ims-countdown.php:145
actionadmin_enqueue_scriptsincludes\class-ims-countdown.php:159
actionadmin_enqueue_scriptsincludes\class-ims-countdown.php:160
actioninitincludes\class-ims-countdown.php:161
actionadmin_menuincludes\class-ims-countdown.php:162
actionadmin_initincludes\class-ims-countdown.php:163
actionadd_meta_boxesincludes\class-ims-countdown.php:164
actionsave_postincludes\class-ims-countdown.php:165
actionwp_enqueue_scriptsincludes\class-ims-countdown.php:179
actionwp_enqueue_scriptsincludes\class-ims-countdown.php:180
Maintenance & Trust

IMS Countdown Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 25, 2025
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

IMS Countdown Developer Profile

Acewebx

7 plugins · 340 total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
330 days
View full developer profile
Detection Fingerprints

How We Detect IMS Countdown

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ims-countdown/css/ims-countdown-admin.css/wp-content/plugins/ims-countdown/css/admin.css/wp-content/plugins/ims-countdown/css/jquery.datetimepicker.css/wp-content/plugins/ims-countdown/css/spectrum.css/wp-content/plugins/ims-countdown/js/ims-countdown-admin.js/wp-content/plugins/ims-countdown/js/jquery.datetimepicker.full.min.js/wp-content/plugins/ims-countdown/js/spectrum.js/wp-content/plugins/ims-countdown/js/admin-custom.js
Script Paths
/wp-content/plugins/ims-countdown/js/ims-countdown-admin.js/wp-content/plugins/ims-countdown/js/jquery.datetimepicker.full.min.js/wp-content/plugins/ims-countdown/js/spectrum.js/wp-content/plugins/ims-countdown/js/admin-custom.js
Version Parameters
ims-countdown-admin-css_styleims-countdown-admin-css_styleims-countdown-datapicker-adminims-countdown-admin-spectrumims-countdown-admin-jsims-countdown-datepicker-jsims-countdown-spectrum-jsims-countdown-admin-js

HTML / DOM Fingerprints

CSS Classes
ims-countdown-clock
Data Attributes
data-daysdata-hoursdata-minutesdata-secondsdata-datedata-timezone
JS Globals
ims_countdown_params
Shortcode Output
[ims_countdown[ims_countdown
FAQ

Frequently Asked Questions about IMS Countdown