
Timetics – Appointment Booking Calendar & Scheduling System Security & Risk Analysis
wordpress.org/plugins/timeticsAppointment booking system for Professionals — schedule, manage calendars, accept payments, send reminders & automate bookings easily.
Is Timetics – Appointment Booking Calendar & Scheduling System Safe to Use in 2026?
Generally Safe
Score 86/100Timetics – Appointment Booking Calendar & Scheduling System has a strong security track record. Known vulnerabilities have been patched promptly.
The "timetics" plugin v1.0.53 exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and a high percentage of output escaping (85%), significant concerns arise from its attack surface. Specifically, 3 out of 7 identified entry points are AJAX handlers lacking authentication checks, presenting a direct avenue for potential unauthorized actions. The taint analysis shows no critical or high-severity issues, which is a positive sign regarding immediate code execution risks. However, the plugin's vulnerability history is a major red flag. With 8 known CVEs, including one critical and one high-severity vulnerability, and a recent vulnerability reported in 2026, it suggests a recurring pattern of authorization-related weaknesses that may not be fully mitigated. The fact that none of the historical vulnerabilities are currently unpatched is a small positive, but the sheer number and nature of past issues warrant caution.
In conclusion, while the code quality regarding SQL and output escaping is commendable, the lack of authorization checks on a portion of its AJAX handlers and its history of critical and high-severity authorization bypass vulnerabilities point to a significant ongoing risk. Users should be aware that despite current unpatched vulnerabilities being zero, the plugin has a history of exploitable authorization flaws that could resurface or remain undetected.
Key Concerns
- 3 unprotected AJAX handlers
- 8 known CVEs (1 critical, 1 high)
- Authorization bypass vulnerability history
Timetics – Appointment Booking Calendar & Scheduling System Security Vulnerabilities
CVEs by Year
Severity Breakdown
8 total CVEs
Appointment Booking and Scheduling Calendar Plugin – WP Timetics <= 1.0.36 - Missing Authorization to Unauthenticated Booking Details View And Modification
Timetics <= 1.0.46 - Incorrect Authorization to Authenticated (Timetics Customer+) User Creation
Timetics <= 1.0.44 - Missing Authorization
Timetics <= 1.0.29 - Missing Authorization
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin <= 1.0.27 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Deletion
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin <= 1.0.25 - Insecure Direct Object Reference to Unauthenticated Arbitrary User Password/Email Reset/Account Takeover
Timetics <= 1.0.23 - Authorization Bypass
Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling Plugin <= 1.0.21 - Missing Authorization to Limited Privilege Escalation
Timetics – Appointment Booking Calendar & Scheduling System Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Timetics – Appointment Booking Calendar & Scheduling System Attack Surface
AJAX Handlers 3
Shortcodes 4
WordPress Hooks 77
Scheduled Events 1
Maintenance & Trust
Timetics – Appointment Booking Calendar & Scheduling System Maintenance & Trust
Maintenance Signals
Community Trust
Timetics – Appointment Booking Calendar & Scheduling System Alternatives
Easy Appointment Booking & Scheduling System – Webba Booking Calendar
webba-booking-lite
Free Appointment Booking Plugin 📅 Unlimited appointments, booking management, calendar sync, notifications, 5* support = powerful booking system!
Ultimate Appointment Booking & Scheduling
ultimate-appointment-scheduling
Appointment booking calendar and scheduling plugin that lets you set up different services, service providers, locations and availability
Sugar Calendar Bookings Scheduling Appointments Lite
sugar-calendar-bookings-scheduling-appointments-lite
The easiest appointment booking plugin for WordPress. Create booking forms, manage services & schedules, and accept Stripe payments.
Online Scheduling and Appointment Booking System – Bookly
bookly-responsive-appointment-booking-tool
Appointment booking system for WordPress — schedule appointments, manage calendars, send reminders, take payments. Start booking today!
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin
simply-schedule-appointments
Unlimited appointments, booking calendars, and notifications. Powerful appointment booking plugin and booking system. Start scheduling for free today!
Timetics – Appointment Booking Calendar & Scheduling System Developer Profile
8 plugins · 20K total installs
How We Detect Timetics – Appointment Booking Calendar & Scheduling System
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/timetics/assets/css/backend.css/wp-content/plugins/timetics/assets/css/frontend.css/wp-content/plugins/timetics/assets/js/backend.js/wp-content/plugins/timetics/assets/js/frontend.jstimetics/assets/css/backend.css?ver=timetics/assets/css/frontend.css?ver=timetics/assets/js/backend.js?ver=timetics/assets/js/frontend.js?ver=HTML / DOM Fingerprints
timetics-booking-calendartimetics-appointments-wrapTimetics Essential is distributed in the hope that it will be usefulTimetics is free software: you can redistribute it and/or modifydata-timetics-bookingdata-timetics-appointment-idtimeticsApptimetics/timetics/v1/feedback[timetics_booking_form][timetics_calendar]