
Post Worktime Logger Security & Risk Analysis
wordpress.org/plugins/post-worktime-loggerPost Worktime Logger is a WordPress plugin that allows you to track the time you worked on each post.
Is Post Worktime Logger Safe to Use in 2026?
Generally Safe
Score 85/100Post Worktime Logger has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'post-worktime-logger' plugin v1.5.3 exhibits a concerning security posture primarily due to its unprotected AJAX handlers. While the plugin demonstrates good practices in its handling of SQL queries through prepared statements and a lack of external HTTP requests or file operations, the presence of two AJAX entry points without any authentication or capability checks creates a significant attack vector. This means that any unauthenticated user could potentially trigger actions within these handlers, leading to unintended consequences or the execution of sensitive operations.
The taint analysis reveals flows with unsanitized paths, indicating a potential for privilege escalation or unauthorized data access if these paths are exploited through the unprotected AJAX endpoints. The code signals also highlight a weakness in output escaping, with only 32% of outputs being properly escaped. This could pave the way for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not adequately sanitized before being displayed.
The vulnerability history of this plugin is currently clean, with no recorded CVEs. This is a positive indicator, suggesting that historically the plugin has not been a target or has been maintained with reasonable security in mind. However, the absence of past vulnerabilities should not lead to complacency, especially given the current static analysis findings. The primary concerns revolve around the unprotected AJAX handlers and potential XSS risks, which, despite a clean history, represent actionable weaknesses that attackers could exploit.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Low output escaping percentage
- Missing nonce checks on AJAX
Post Worktime Logger Security Vulnerabilities
Post Worktime Logger Code Analysis
Output Escaping
Data Flow Analysis
Post Worktime Logger Attack Surface
AJAX Handlers 2
WordPress Hooks 13
Maintenance & Trust
Post Worktime Logger Maintenance & Trust
Maintenance Signals
Community Trust
Post Worktime Logger Alternatives
HRM Work Tracking
hrm-work-tracking
HRM Work Tracking plugin is a complete employee or user time tracking in the WordPress backend.
Countdown Timer Ultimate
countdown-timer-ultimate
A quick, easy way to add and display responsive Countdown timer on your website. Also work with Gutenberg shortcode block.
User Activity Tracking and Log
user-activity-tracking-and-log
Track time and monitor user activity & history on your website, LMS online learning system, membership or WooCommerce site.
MX Time Zone Clocks
mx-time-zone-clocks
Add time zone clocks to your website.
Simple Countdown Timer
simple-countdown
Simple Countdown Timer Plugin allows you to easily create and customize countdown timers for your website. Whether you're counting down to a sale …
Post Worktime Logger Developer Profile
2 plugins · 50 total installs
How We Detect Post Worktime Logger
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/post-worktime-logger/resources/css/post-worktime-logger.css/wp-content/plugins/post-worktime-logger/resources/js/Chart.bundle.min.js/wp-content/plugins/post-worktime-logger/resources/js/post-worktime-logger.jsresources/js/Chart.bundle.min.jsresources/js/post-worktime-logger.jsHTML / DOM Fingerprints
pwl-buttonid="post-worktime-logger-current-post-id"id="frontendTime"id="serverWorktime"id="pwl-pause-button"id="pwl-resume-button"id="pwl-reset-button"pwl