
Timetics – Appointment Booking Calendar & Scheduling System Security & Risk Analysis
wordpress.org/plugins/timeticsOnline booking and scheduling system for appointments, meetings, consultations, classes, payments, reminders, and calendar sync.
Is Timetics – Appointment Booking Calendar & Scheduling System Safe to Use in 2026?
Mostly Safe
Score 83/100Timetics – Appointment Booking Calendar & Scheduling System is generally safe to use. 11 past CVEs were resolved.
The "timetics" plugin v1.0.53 exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and a high percentage of output escaping (85%), significant concerns arise from its attack surface. Specifically, 3 out of 7 identified entry points are AJAX handlers lacking authentication checks, presenting a direct avenue for potential unauthorized actions. The taint analysis shows no critical or high-severity issues, which is a positive sign regarding immediate code execution risks. However, the plugin's vulnerability history is a major red flag. With 8 known CVEs, including one critical and one high-severity vulnerability, and a recent vulnerability reported in 2026, it suggests a recurring pattern of authorization-related weaknesses that may not be fully mitigated. The fact that none of the historical vulnerabilities are currently unpatched is a small positive, but the sheer number and nature of past issues warrant caution.
In conclusion, while the code quality regarding SQL and output escaping is commendable, the lack of authorization checks on a portion of its AJAX handlers and its history of critical and high-severity authorization bypass vulnerabilities point to a significant ongoing risk. Users should be aware that despite current unpatched vulnerabilities being zero, the plugin has a history of exploitable authorization flaws that could resurface or remain undetected.
Key Concerns
- 3 unprotected AJAX handlers
- 8 known CVEs (1 critical, 1 high)
- Authorization bypass vulnerability history
Timetics – Appointment Booking Calendar & Scheduling System Security Vulnerabilities
CVEs by Year
Severity Breakdown
11 total CVEs
Timetics – Appointment Booking Calendar & Scheduling System <= 1.0.58 - Unauthenticated Stored Cross-Site Scripting
Timetics – Appointment Booking & Scheduling <= 1.0.53 - Missing Authorization
Timetics – Appointment Booking Calendar & Scheduling System < 1.0.52 - Missing Authorization
Appointment Booking and Scheduling Calendar Plugin – WP Timetics <= 1.0.36 - Missing Authorization to Unauthenticated Booking Details View And Modification
Timetics <= 1.0.46 - Incorrect Authorization to Authenticated (Timetics Customer+) User Creation
Timetics <= 1.0.44 - Missing Authorization
Timetics <= 1.0.29 - Missing Authorization
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin <= 1.0.27 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Deletion
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin <= 1.0.25 - Insecure Direct Object Reference to Unauthenticated Arbitrary User Password/Email Reset/Account Takeover
Timetics <= 1.0.23 - Authorization Bypass
Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling Plugin <= 1.0.21 - Missing Authorization to Limited Privilege Escalation
Timetics – Appointment Booking Calendar & Scheduling System Release Timeline
Timetics – Appointment Booking Calendar & Scheduling System Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Timetics – Appointment Booking Calendar & Scheduling System Attack Surface
AJAX Handlers 3
Shortcodes 4
WordPress Hooks 77
Scheduled Events 1
Maintenance & Trust
Timetics – Appointment Booking Calendar & Scheduling System Maintenance & Trust
Maintenance Signals
Community Trust
Timetics – Appointment Booking Calendar & Scheduling System Alternatives
Cal.com
cal-com
Embed Cal.com booking calendar in WordPress with custom UI and admin widget support.
Appointment Bookings for Zoom GoogleMeet and more – Wappointment
wappointment
Get clients to quickly book a meeting with you by Zoom, GoogleMeet, phone or at your office
TrueBooker – Appointment Booking and Scheduler System
truebooker-appointment-booking
Book appointments, create booking with TrueBooker. Easily create appointments, manage time and dates and send out emails.
Easy Booked – Appointment Booking and Scheduling Management System for WordPress
easy-booked
A comprehensive appointment booking calendar and scheduling management system for WordPress.
Sugar Calendar Bookings Scheduling Appointments Lite
sugar-calendar-bookings-scheduling-appointments-lite
The easiest appointment booking plugin for WordPress. Create booking forms, manage services & schedules, and accept Stripe payments.
Timetics – Appointment Booking Calendar & Scheduling System Developer Profile
13 plugins · 19K total installs
How We Detect Timetics – Appointment Booking Calendar & Scheduling System
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/timetics/assets/css/backend.css/wp-content/plugins/timetics/assets/css/frontend.css/wp-content/plugins/timetics/assets/js/backend.js/wp-content/plugins/timetics/assets/js/frontend.jstimetics/assets/css/backend.css?ver=timetics/assets/css/frontend.css?ver=timetics/assets/js/backend.js?ver=timetics/assets/js/frontend.js?ver=HTML / DOM Fingerprints
timetics-booking-calendartimetics-appointments-wrapTimetics Essential is distributed in the hope that it will be usefulTimetics is free software: you can redistribute it and/or modifydata-timetics-bookingdata-timetics-appointment-idtimeticsApptimetics/timetics/v1/feedback[timetics_booking_form][timetics_calendar]