
Time goes by Security & Risk Analysis
wordpress.org/plugins/time-goes-bySwitch the display of content based on time using a shortcode. ショートコードで囲んだコンテンツを時間に応じて表示切替できるプラグイン。
Is Time goes by Safe to Use in 2026?
Generally Safe
Score 100/100Time goes by has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "time-goes-by" plugin version 1.2.9.1 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, cron events, and external HTTP requests significantly limits its attack surface. Furthermore, all SQL queries are prepared, and there are no recorded vulnerabilities or CVEs, indicating a history of stable and secure development. The plugin also avoids dangerous functions and file operations, which are common sources of security weaknesses.
However, there are areas for improvement. The presence of 4 shortcodes presents a potential entry point, and while the analysis found no unprotected shortcodes in this specific run, shortcodes can still be exploited if not carefully handled. A notable concern is that 30% of the total outputs are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is reflected in these outputs without adequate sanitization. Additionally, the lack of nonce checks and capability checks on the identified entry points is a significant security gap, as it means actions initiated through shortcodes are not properly verified for user authorization, potentially allowing unauthorized users to trigger plugin functionalities. The taint analysis showing flows with unsanitized paths, though not critical or high severity, warrants attention.
In conclusion, while the plugin has a clean vulnerability history and a low attack surface in terms of external interactions, the unescaped outputs and missing authorization checks on its shortcode entry points represent the most significant risks. Addressing these would greatly enhance the plugin's overall security. The absence of security concerns in vulnerability history is a positive indicator of past development practices.
Key Concerns
- Unescaped output
- Missing nonce checks
- Missing capability checks
- Flows with unsanitized paths
Time goes by Security Vulnerabilities
Time goes by Code Analysis
Output Escaping
Data Flow Analysis
Time goes by Attack Surface
Shortcodes 4
WordPress Hooks 1
Maintenance & Trust
Time goes by Maintenance & Trust
Maintenance Signals
Community Trust
Time goes by Alternatives
JKL Timezone Converter
jkl-timezone-converter
A simple Timezone widget and shortcode that allows you to convert time differences and easily plan events or meetings based in other timezones.
Pravin Smart Content Scheduler
pravin-smart-content-scheduler
Schedule content visibility based on dates, times, and user roles with a simple shortcode.
Time-Limited Content Access
time-limited-content-access
Show or hide content based on a date/time range using a simple shortcode.
Content Blocks (Custom Post Widget)
custom-post-widget
This plugin enables you to edit and display Content Blocks in a sidebar widget or using a shortcode.
WP Date and Time Shortcode
wp-date-and-time-shortcode
Shortcode to show any current, past, and future date or time. Display this, previous, or next year, month, day, etc.
Time goes by Developer Profile
2 plugins · 20K total installs
How We Detect Time goes by
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/time-goes-by/js/tgb.js/wp-content/plugins/time-goes-by/js/tgb.jsHTML / DOM Fingerprints
name="timezone"value="Europe\/London"[tgb][disp_content][disp_title][disp_excerpt]