Plain Tracker Security & Risk Analysis
wordpress.org/plugins/plaintrackerA time clock plugin to track and analyze time of employees, workers or volunteers.
Is Plain Tracker Safe to Use in 2026?
Generally Safe
Score 100/100Plain Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plaintracker v3.1.1 plugin exhibits a generally strong security posture based on the provided static analysis. A significant strength is the complete absence of known vulnerabilities (CVEs) and the use of prepared statements for all SQL queries. The code also demonstrates a good practice of performing capability checks on its entry points. However, there are areas for improvement. The low percentage of properly escaped output (62%) suggests a potential for cross-site scripting (XSS) vulnerabilities, especially if the unsanitized outputs involve user-controlled data. The lack of nonce checks on its single entry point (the shortcode) is also a concern, as it could potentially lead to unauthorized actions if the shortcode's functionality is sensitive. The absence of taint analysis results is noted but doesn't necessarily indicate a weakness without further context.
While the plugin has no recorded vulnerability history, which is a positive indicator, the static analysis reveals specific areas that require attention. The primary concerns are the insufficient output escaping and the missing nonce checks. These could be exploited to inject malicious scripts or trigger unintended actions. Overall, plaintracker v3.1.1 is not inherently insecure, but it does present some manageable risks that could be addressed through more rigorous input validation and output sanitization, as well as the implementation of nonce checks.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks on shortcode
Plain Tracker Security Vulnerabilities
Plain Tracker Code Analysis
SQL Query Safety
Output Escaping
Plain Tracker Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Plain Tracker Maintenance & Trust
Maintenance Signals
Community Trust
Plain Tracker Alternatives
Time Clock – A WordPress Employee & Volunteer Time Clock Plugin
time-clock
An employee / volunteer time clock for WordPress
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier
aio-time-clock-lite
Employees can easily clock in and out. Managers can run reports, keep track of employees/volunteers/contractors and their time.
Attendance Manager
attendance-manager
Each user can do attendance management by themselves. 管理者のほか、ユーザー自身も編集可能な出勤管理プラグイン。
ShiftController Employee Shift Scheduling
shiftcontroller
Schedule staff and shifts anywhere at anytime online from your WordPress powered website.
Clock In Portal- Staff & Attendance Management
clock-in-portal
Track the attendance of all registered employees with clock in or out system
Plain Tracker Developer Profile
5 plugins · 2K total installs
How We Detect Plain Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/plaintracker/assets/css/plaintracker.css/wp-content/plugins/plaintracker/assets/js/plaintracker.js/wp-content/plugins/plaintracker/assets/js/plaintracker.jsplaintracker/assets/css/plaintracker.css?ver=plaintracker/assets/js/plaintracker.js?ver=HTML / DOM Fingerprints
plaintracker-wrapplaintracker-login<!-- Generated by Plain Tracker -->data-plaintracker-login-urldata-plaintracker-login-noncedata-plaintracker-login-ajax-urlPlainwarePlaintracker31/wp-json/plaintracker/v3<div class="plaintracker-wrap">