
Time Clock – A WordPress Employee & Volunteer Time Clock Plugin Security & Risk Analysis
wordpress.org/plugins/time-clockAn employee / volunteer time clock for WordPress
Is Time Clock – A WordPress Employee & Volunteer Time Clock Plugin Safe to Use in 2026?
Generally Safe
Score 95/100Time Clock – A WordPress Employee & Volunteer Time Clock Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The "time-clock" plugin v1.3.2 presents a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and appears to have no currently unpatched CVEs. The taint analysis also shows a clean bill of health with no identified unsanitized flows. However, significant concerns arise from the static analysis. The presence of one AJAX handler without authentication checks creates a direct entry point for unauthenticated attackers. Furthermore, the plugin utilizes the deprecated and inherently insecure `create_function` PHP function twice, which is a strong indicator of potential code injection vulnerabilities if not handled with extreme care. While the vulnerability history shows no current critical issues, the past prevalence of Cross-site Scripting and Code Injection vulnerabilities, along with a high-severity CVE recorded recently, suggests a recurring pattern of insecure coding practices that require vigilant monitoring and patching.
Key Concerns
- Unprotected AJAX handler found
- Use of dangerous function 'create_function'
- Low output escaping rate (43%)
- Past high-severity CVEs and common vuln types
Time Clock – A WordPress Employee & Volunteer Time Clock Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Time Clock – A WordPress Employee & Volunteer Time Clock Plugin <= 1.3.1 - Authenticated (Custom+) Stored Cross-Site Scripting
Time Clock <= 1.2.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
Time Clock <= 1.2.2 & Time Clock Pro <= 1.1.4 - Unauthenticated (Limited) Remote Code Execution
Time Clock – A WordPress Employee & Volunteer Time Clock Plugin Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Time Clock – A WordPress Employee & Volunteer Time Clock Plugin Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 39
Maintenance & Trust
Time Clock – A WordPress Employee & Volunteer Time Clock Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Time Clock – A WordPress Employee & Volunteer Time Clock Plugin Alternatives
Plain Tracker
plaintracker
A time clock plugin to track and analyze time of employees, workers or volunteers.
All in One Time Clock Lite – Tracking Employee Time Has Never Been Easier
aio-time-clock-lite
Employees can easily clock in and out. Managers can run reports, keep track of employees/volunteers/contractors and their time.
HRM Work Tracking
hrm-work-tracking
HRM Work Tracking plugin is a complete employee or user time tracking in the WordPress backend.
Countdown Timer Ultimate
countdown-timer-ultimate
A quick, easy way to add and display responsive Countdown timer on your website. Also work with Gutenberg shortcode block.
MX Time Zone Clocks
mx-time-zone-clocks
Add time zone clocks to your website.
Time Clock – A WordPress Employee & Volunteer Time Clock Plugin Developer Profile
12 plugins · 44K total installs
How We Detect Time Clock – A WordPress Employee & Volunteer Time Clock Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/time-clock/assets/css/etimeclockwp-admin.css/wp-content/plugins/time-clock/assets/js/etimeclockwp-deactivation-survey.js/wp-content/plugins/time-clock/assets/js/etimeclockwp-deactivation-survey.jsplugins/time-clock/assets/js/etimeclockwp-deactivation-survey.js?ver=plugins/time-clock/assets/css/etimeclockwp-admin.css?ver=HTML / DOM Fingerprints
etimeclockwp-deactivation-survey-modaletimeclockwp-deactivation-survey-backdropetimeclockwp-survey-fieldetimeclockwp-survey-textareaetimeclockwp-survey-radiodata-etimeclockwp-plugin-versionetimeclockwpDeactivationSurvey