
Timetable Security & Risk Analysis
wordpress.org/plugins/plan-lekcjiA WordPress plugin for managing school timetables based on files generated by Vulcan Optivum, allowing ZIP file uploads.
Is Timetable Safe to Use in 2026?
Generally Safe
Score 100/100Timetable has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plan-lekcji v2.7.3 plugin demonstrates a generally strong security posture, with an impressive 100% of SQL queries using prepared statements and a high rate of output escaping (92%). The absence of known vulnerabilities in its history, critical taint flows, or dangerous functions is highly commendable. This indicates a developer who is conscious of common web security pitfalls.
However, the plugin is not without its concerns. The presence of one unprotected REST API route represents a significant attack vector. While the total attack surface is small, this single unprotected entry point could potentially be exploited. The limited number of capability checks and nonces, although not directly pointing to a vulnerability given the current code signals, suggests a potential for future issues if the plugin's functionality expands without commensurate security enhancements.
In conclusion, plan-lekcji v2.7.3 is a relatively secure plugin, primarily due to its robust data handling and lack of historical issues. The key weakness lies in the unprotected REST API route. Addressing this single entry point should be the immediate priority to further solidify its security.
Key Concerns
- Unprotected REST API route
Timetable Security Vulnerabilities
Timetable Code Analysis
Output Escaping
Data Flow Analysis
Timetable Attack Surface
AJAX Handlers 2
REST API Routes 1
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
Timetable Maintenance & Trust
Maintenance Signals
Community Trust
Timetable Alternatives
Timetable and Event Schedule by MotoPress
mp-timetable
Smart event organizer and time-management tool with a clean minimalist design for featuring your timetables and upcoming events.
MainWP Key Maker
mainwp-key-maker
The MainWP Key Maker plugin copies settings for the MainWP Bulk Settings Manager Extension.
WPC Product Timer for WooCommerce
woo-product-timer
WPC Product Timer helps you add many actions for the product based on the conditionals of the time.
Cron Jobs
leira-cron-jobs
Easily manage and monitor your WordPress cron jobs from a clean, intuitive interface.
Easy PHP Settings
easy-php-settings
An easy way to manage common PHP INI settings and WordPress debugging constants from the WordPress admin panel.
Timetable Developer Profile
1 plugin · 0 total installs
How We Detect Timetable
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/plan-lekcji/css/styles1.css/wp-content/plugins/plan-lekcji/css/dobry_plan.css/wp-content/plugins/plan-lekcji/js/menu.js/wp-content/plugins/plan-lekcji/js/printTableScript.js/wp-content/plugins/plan-lekcji/js/dobry_plan.js/wp-content/plugins/plan-lekcji/js/menu.js/wp-content/plugins/plan-lekcji/js/printTableScript.js/wp-content/plugins/plan-lekcji/js/dobry_plan.jsplan-lekcji/css/styles1.css?ver=plan-lekcji/css/dobry_plan.css?ver=plan-lekcji/js/menu.js?ver=plan-lekcji/js/printTableScript.js?ver=plan-lekcji/js/dobry_plan.js?ver=HTML / DOM Fingerprints
tabelatytulnapisclass="tabela"cellspacing="0"cellpadding="4"border="1"planle_ajaxwindow.planle_ajax/planle/v1/sse-endpoint/<p style="color:red;">Please select a plan generator in settings.</p>