
Localize Time Security & Risk Analysis
wordpress.org/plugins/localize-timeProvides a [localize_time] shortcode, which displays times in the user's local timezone.
Is Localize Time Safe to Use in 2026?
Generally Safe
Score 85/100Localize Time has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "localize-time" v1.0.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, unescaped output, file operations, and external HTTP requests are all positive indicators. Furthermore, the plugin does not appear to utilize any bundled libraries, which can sometimes introduce vulnerabilities if outdated. The lack of any recorded vulnerabilities in its history, including critical or high severity issues, further reinforces its perceived safety. The minimal attack surface, consisting of a single shortcode with no obvious unauthenticated entry points, is also a significant strength.
However, a notable concern is the complete absence of nonce and capability checks across all identified entry points. While the static analysis reports zero unprotected entry points, the lack of these fundamental WordPress security mechanisms means that even the single shortcode could potentially be abused if a determined attacker finds a way to trigger it without proper authorization or validation. The reported zero taint flows are good, but this is often a reflection of the analysis's depth and might not catch all sophisticated injection vectors, especially without the presence of input validation and authorization checks. Overall, the plugin has a good foundation with clean code practices but the missing authentication and authorization checks represent a significant, albeit potentially manageable, weakness.
Key Concerns
- Missing nonce checks
- Missing capability checks
Localize Time Security Vulnerabilities
Localize Time Code Analysis
Localize Time Attack Surface
Shortcodes 1
Maintenance & Trust
Localize Time Maintenance & Trust
Maintenance Signals
Community Trust
Localize Time Alternatives
Global Time Ghost – Local Time Converter
global-time-ghost
Show any UTC time in the visitor's real local timezone — automatically. Gutenberg block + shortcode. Zero config. Works with every cache & CDN.
Simple Digital Clock 🕒
simple-digital-clock
It is 🪄 a magical and easy-to-use digital clock with a beautiful UI, supporting multiple languages, locales, dates, captions, and time zones.
IP2Location World Clock
ip2location-world-clock
Simple world clock widget to display analog or digital clock for multiple time zone on your site. Supported local time, visitor's time and custom …
Simple Location
simple-location
Adds geographic location and weather support to WordPress.
Current Date & Time Widget
current-date-time-widget
Provides a widget that shows the current date and time given a specified timezone and format.
Localize Time Developer Profile
1 plugin · 40 total installs
How We Detect Localize Time
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/localize-time/localize-time.js/wp-content/plugins/localize-time/localize-time.jsHTML / DOM Fingerprints
localize_time_origlocalize_time_localerrordata-timestampdata-offsetdata-beforedata-after<span class='localize_time_orig'></span><span class='localize_time_local'