SD Timer – Live Time Tracker for Frontend & Backend Security & Risk Analysis

wordpress.org/plugins/sd-timer

Best Time Tracker Plugin for WordPress websites. Make time management easier and simple.

0 active installs v1.0.1 PHP 7.2+ WP 6.7+ Updated Unknown
countertime-managementtime-trackertimerwp-time-tracker
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is SD Timer – Live Time Tracker for Frontend & Backend Safe to Use in 2026?

Generally Safe

Score 100/100

SD Timer – Live Time Tracker for Frontend & Backend has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "sd-timer" v1.0.1 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the proper escaping of all outputs indicate adherence to secure coding practices. Furthermore, the implementation of nonce checks for its two AJAX entry points is a positive security control. The lack of any known CVEs, past or present, and the absence of recorded common vulnerability types suggest a history of secure development or timely patching.

However, a notable area for improvement is the absence of capability checks on its AJAX handlers. While nonce checks protect against cross-site request forgery, they do not prevent authenticated users with lower privileges from accessing functionality intended for administrators. The taint analysis showing zero flows, while generally positive, could also be interpreted as a lack of complex data handling that might expose such vulnerabilities in other scenarios. The plugin's current vulnerability-free status is a significant strength, but the reliance solely on nonce checks for AJAX, without capability checks, presents a potential weakness for privilege escalation if the AJAX actions are sensitive.

In conclusion, "sd-timer" v1.0.1 is currently a low-risk plugin due to its robust handling of SQL and output, alongside a clean vulnerability history. The main area of concern is the lack of explicit capability checks on its AJAX endpoints, which could be exploited by authenticated but unauthorized users. Addressing this would further solidify its security.

Key Concerns

  • Missing capability checks on AJAX handlers
Vulnerabilities
None known

SD Timer – Live Time Tracker for Frontend & Backend Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

SD Timer – Live Time Tracker for Frontend & Backend Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped5 total outputs
Attack Surface

SD Timer – Live Time Tracker for Frontend & Backend Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_sdtimer_save_timesd-timer.php:121
authwp_ajax_sdtimer_get_timesd-timer.php:135
WordPress Hooks 4
actionwp_enqueue_scriptssd-timer.php:32
actionadmin_enqueue_scriptssd-timer.php:33
actionadmin_menusd-timer.php:47
actionadmin_bar_menusd-timer.php:94
Maintenance & Trust

SD Timer – Live Time Tracker for Frontend & Backend Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.2
Downloads892

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

SD Timer – Live Time Tracker for Frontend & Backend Developer Profile

Sadhan Pal

9 plugins · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect SD Timer – Live Time Tracker for Frontend & Backend

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sd-timer/includes/style.css/wp-content/plugins/sd-timer/includes/script.js
Script Paths
jquery
Version Parameters
sd-timer/includes/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
sdtimer-settings-containersdtimer-formsdtimer-input-groupsdtimer-counter
Data Attributes
id="sdtimer-session-counter"id="sdtimer-total-counter"id="working-hours"id="working-minutes"id="sdtimer-save"
JS Globals
sdtimerData
FAQ

Frequently Asked Questions about SD Timer – Live Time Tracker for Frontend & Backend