jClocksGMT World Clocks Security & Risk Analysis

wordpress.org/plugins/jclocksgmt-wp

jQuery based analog and digital world clocks for Wordpress.

100 active installs v1.0.2 PHP + WP 3.0.1+ Updated May 20, 2016
clocktimetimezoneworld-clock
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is jClocksGMT World Clocks Safe to Use in 2026?

Generally Safe

Score 85/100

jClocksGMT World Clocks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The jclocksgmt-wp plugin, version 1.0.2, exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates excellent adherence to secure coding practices by utilizing prepared statements for all SQL queries and ensuring all output is properly escaped. Furthermore, the absence of file operations, external HTTP requests, and dangerous functions significantly reduces the potential for common web vulnerabilities. The plugin also scores well by not bundling any external libraries, which can often be a source of outdated or vulnerable code.

However, there are some areas that warrant caution. The static analysis reveals no explicit capability checks or nonce checks. While the attack surface is minimal (consisting of a single shortcode), the absence of these checks could, in theory, allow unauthorized users to interact with the shortcode's functionality if it were to expose sensitive operations. This is particularly concerning given the total lack of any recorded vulnerability history, which could suggest a lack of thorough security testing or an incomplete picture of potential weaknesses.

In conclusion, jclocksgmt-wp appears to be built with good fundamental security principles, especially regarding data handling. The lack of known vulnerabilities is a positive indicator. Nevertheless, the absence of authorization checks (capability and nonce) on its sole entry point, the shortcode, represents a potential weakness that could be exploited if the shortcode's functionality were to have any security implications. Developers should consider implementing appropriate authorization checks to further harden the plugin.

Key Concerns

  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

jClocksGMT World Clocks Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

jClocksGMT World Clocks Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

jClocksGMT World Clocks Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[jclocksgmt] jclocksgmt-wp.php:54
WordPress Hooks 1
actionthe_postsjclocksgmt-wp.php:52
Maintenance & Trust

jClocksGMT World Clocks Maintenance & Trust

Maintenance Signals

WordPress version tested4.5.33
Last updatedMay 20, 2016
PHP min version
Downloads6K

Community Trust

Rating74/100
Number of ratings3
Active installs100
Developer Profile

jClocksGMT World Clocks Developer Profile

kingkode

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect jClocksGMT World Clocks

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/jclocksgmt-wp/css/jClocksGMT.css/wp-content/plugins/jclocksgmt-wp/js/jquery.rotate.js/wp-content/plugins/jclocksgmt-wp/js/jClocksGMT.js
Script Paths
js/jquery.rotate.jsjs/jClocksGMT.js
Version Parameters
jclocksgmt-wp/css/jClocksGMT.css?ver=jclocksgmt-wp/js/jquery.rotate.js?ver=jclocksgmt-wp/js/jClocksGMT.js?ver=

HTML / DOM Fingerprints

CSS Classes
jclockgmt
Shortcode Output
<div id="clock_</div><script>jQuery(document).ready(function(){jQuery("#clock_
FAQ

Frequently Asked Questions about jClocksGMT World Clocks