
IP2Location World Clock Security & Risk Analysis
wordpress.org/plugins/ip2location-world-clockSimple world clock widget to display analog or digital clock for multiple time zone on your site. Supported local time, visitor's time and custom …
Is IP2Location World Clock Safe to Use in 2026?
Generally Safe
Score 99/100IP2Location World Clock has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'ip2location-world-clock' plugin v1.2.1 presents a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and avoids external HTTP requests. The absence of bundled libraries and a low number of file operations are also encouraging. However, significant concerns arise from the presence of an unprotected AJAX handler, which forms a critical part of its attack surface. The taint analysis also reveals a flow with an unsanitized path, though it's not classified as critical or high severity. The plugin's vulnerability history indicates a past medium-severity CVE, specifically a Cross-Site Request Forgery (CSRF), which, while currently patched, suggests a pattern of potential vulnerabilities that require careful management.
Overall, while the plugin has some strong security foundations, the unprotected entry point and the unsanitized path flow expose it to specific risks. The past CSRF vulnerability, even if fixed, warrants continued vigilance. The lack of capability checks on any entry points is a notable weakness that could be exploited in conjunction with other vulnerabilities. Given these factors, users should be cautious and ensure the plugin is updated to the latest version, though this analysis is based on v1.2.1.
Key Concerns
- Unprotected AJAX handler
- Flow with unsanitized path
- Low output escaping percentage
- No capability checks
- Medium severity CVE in history
IP2Location World Clock Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
IP2Location World Clock <= 1.1.9 - Cross-Site Request Forgery to Stored Cross-Site Scripting
IP2Location World Clock Release Timeline
IP2Location World Clock Code Analysis
Output Escaping
Data Flow Analysis
IP2Location World Clock Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
IP2Location World Clock Maintenance & Trust
Maintenance Signals
Community Trust
IP2Location World Clock Alternatives
Simple Digital Clock 🕒
simple-digital-clock
It is 🪄 a magical and easy-to-use digital clock with a beautiful UI, supporting multiple languages, locales, dates, captions, and time zones.
Clock Tik Tik
clock-tik-tik
With this plugin you can now easily customize WooCommerce My Account Page and add custom options related to your Pages.
Universal Clocks
universal-clocks
Elegant and easy to use plugin to add a wide range of clocks on your website!
What Time Is It?
what-time-is-it
A lightweight plugin to display clock widgets on your website.
World Clock Dropdown with ShortCodes
world-clock-with-drop-down-shortcodes
A shortcode plugin to display timezone dropdown with digital clock(local time), with hours, minutes & seconds.
IP2Location World Clock Developer Profile
10 plugins · 39K total installs
How We Detect IP2Location World Clock
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ip2location-world-clock/assets/css/style.css/wp-content/plugins/ip2location-world-clock/assets/js/script.jsip2location-world-clock/assets/css/style.css?ver=ip2location-world-clock/assets/js/script.js?ver=HTML / DOM Fingerprints
iwc-containerdata-clockdatatimeformat<div class="iwc-container"><div id="clock1"><div id="clock2"><div id="clock3">