
StatusDot Security & Risk Analysis
wordpress.org/plugins/statusdotReal-time opening hours with a clean status dot, optional text, and countdown timers.
Is StatusDot Safe to Use in 2026?
Generally Safe
Score 100/100StatusDot has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "statusdot" v2.2.0 plugin demonstrates a generally strong security posture, with no known historical vulnerabilities and a proactive approach to secure coding practices. The static analysis reveals a low attack surface consisting of three entry points, all of which appear to be protected by authentication checks. The plugin also utilizes prepared statements for all SQL queries, avoids dangerous functions, and performs file operations and external HTTP requests, which are positive security indicators.
However, a significant concern arises from the output escaping. With 156 total outputs, only 53% are properly escaped, leaving a substantial portion potentially vulnerable to cross-site scripting (XSS) attacks. While the taint analysis shows no unsanitized flows, the high percentage of unescaped output remains a critical area of risk that could be exploited if an attacker can inject malicious scripts into the data displayed by the plugin. The presence of a bundled library (Freemius v1.0) also warrants attention, as outdated bundled libraries can sometimes introduce vulnerabilities.
In conclusion, while "statusdot" excels in areas like SQL security and avoiding direct vulnerabilities, the significant output escaping deficiency presents a clear and present danger. The lack of historical vulnerabilities is a positive sign, but it does not mitigate the immediate risk posed by the unescaped output. Addressing this issue should be the highest priority to improve the plugin's overall security.
Key Concerns
- Insufficient output escaping
- Bundled library outdated (Freemius v1.0)
StatusDot Security Vulnerabilities
StatusDot Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
StatusDot Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
StatusDot Maintenance & Trust
Maintenance Signals
Community Trust
StatusDot Alternatives
Business Hours Indicator
business-hours-indicator
Display opening hours and if you're currently open/closed, with countdown to next opening. Show or hide content only when open/closed & more!
We’re Open!
opening-hours
Opening hours for your business, a joy to manage and highly customizable. Conditional excerpts; conditional/replacement text; Structured Data for SEO.
Stylish Business Hours
stylish-business-hours
With a sleek design, Stylish Business Hours lets you display your hours in style. Show your opening times however you want and indicate if you're …
Bitkit Opening Hours & Holidays
bitkit-opening-hours-holidays
Manage and display business opening hours, holidays and vacation periods with shortcodes, a Gutenberg block, a widget and JSON-LD structured data.
Gellum Business Hours for WooCommerce
gellum-business-hours
Manage your WooCommerce store's business hours. Disable checkout and display notices when the store is closed, indicating the next opening time.
StatusDot Developer Profile
1 plugin · 0 total installs
How We Detect StatusDot
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/statusdot/assets/css/statusdot-status.css/wp-content/plugins/statusdot/assets/js/statusdot-frontend.js/wp-content/plugins/statusdot/assets/css/statusdot-admin.css/wp-content/plugins/statusdot/assets/js/statusdot-admin.js/wp-content/plugins/statusdot/assets/js/statusdot-frontend.js/wp-content/plugins/statusdot/assets/js/statusdot-admin.jsstatusdot-status?ver=statusdot-frontend?ver=statusdot-admin?ver=HTML / DOM Fingerprints
statusdot-dotstatusdot-labeldata-statusdot-ajax-urldata-statusdot-noncedata-statusdot-pro-noncedata-statusdot-is-prodata-statusdot-revStatusDotDataStatusDotAdmin