
Timetics – Appointment Booking & Scheduling Security & Risk Analysis
wordpress.org/plugins/timeticsAppointment booking and scheduling system with online booking calendar, payments, automated reminders, and calendar sync.
Is Timetics – Appointment Booking & Scheduling Safe to Use in 2026?
Generally Safe
Score 86/100Timetics – Appointment Booking & Scheduling has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "timetics" plugin v1.0.53 exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and a high percentage of output escaping (85%), significant concerns arise from its attack surface. Specifically, 3 out of 7 identified entry points are AJAX handlers lacking authentication checks, presenting a direct avenue for potential unauthorized actions. The taint analysis shows no critical or high-severity issues, which is a positive sign regarding immediate code execution risks. However, the plugin's vulnerability history is a major red flag. With 8 known CVEs, including one critical and one high-severity vulnerability, and a recent vulnerability reported in 2026, it suggests a recurring pattern of authorization-related weaknesses that may not be fully mitigated. The fact that none of the historical vulnerabilities are currently unpatched is a small positive, but the sheer number and nature of past issues warrant caution.
In conclusion, while the code quality regarding SQL and output escaping is commendable, the lack of authorization checks on a portion of its AJAX handlers and its history of critical and high-severity authorization bypass vulnerabilities point to a significant ongoing risk. Users should be aware that despite current unpatched vulnerabilities being zero, the plugin has a history of exploitable authorization flaws that could resurface or remain undetected.
Key Concerns
- 3 unprotected AJAX handlers
- 8 known CVEs (1 critical, 1 high)
- Authorization bypass vulnerability history
Timetics – Appointment Booking & Scheduling Security Vulnerabilities
CVEs by Year
Severity Breakdown
10 total CVEs
Timetics – Appointment Booking & Scheduling <= 1.0.53 - Missing Authorization
Timetics – Appointment Booking Calendar & Scheduling System < 1.0.52 - Missing Authorization
Appointment Booking and Scheduling Calendar Plugin – WP Timetics <= 1.0.36 - Missing Authorization to Unauthenticated Booking Details View And Modification
Timetics <= 1.0.46 - Incorrect Authorization to Authenticated (Timetics Customer+) User Creation
Timetics <= 1.0.44 - Missing Authorization
Timetics <= 1.0.29 - Missing Authorization
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin <= 1.0.27 - Missing Authorization to Authenticated (Subscriber+) Arbitrary User Deletion
WP Timetics- AI-powered Appointment Booking Calendar and Online Scheduling Plugin <= 1.0.25 - Insecure Direct Object Reference to Unauthenticated Arbitrary User Password/Email Reset/Account Takeover
Timetics <= 1.0.23 - Authorization Bypass
Timetics- AI-powered Appointment Booking with Visual Seat Plan and ultimate Calendar Scheduling Plugin <= 1.0.21 - Missing Authorization to Limited Privilege Escalation
Timetics – Appointment Booking & Scheduling Release Timeline
Timetics – Appointment Booking & Scheduling Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Timetics – Appointment Booking & Scheduling Attack Surface
AJAX Handlers 3
Shortcodes 4
WordPress Hooks 77
Scheduled Events 1
Maintenance & Trust
Timetics – Appointment Booking & Scheduling Maintenance & Trust
Maintenance Signals
Community Trust
Timetics – Appointment Booking & Scheduling Alternatives
Easy Appointment Booking & Scheduling System – Webba Booking Calendar
webba-booking-lite
Free Appointment Booking Plugin 📅 Unlimited appointments, booking management, calendar sync, notifications, 5* support = powerful booking system!
Easy Booked – Appointment Booking and Scheduling Management System for WordPress
easy-booked
A comprehensive appointment booking calendar and scheduling management system for WordPress.
Online Scheduling and Appointment Booking System – Bookly
bookly-responsive-appointment-booking-tool
Appointment booking system for WordPress — schedule appointments, manage calendars, send reminders, take payments. Start booking today!
Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin
simply-schedule-appointments
Unlimited appointments, booking calendars, and notifications. Powerful appointment booking plugin and booking system. Start scheduling for free today!
Booking calendar, Appointment Booking System
booking-calendar
Booking calendar plugin is an awesome tool for creating appointment booking calendars and Scheduling systems in a few minutes.
Timetics – Appointment Booking & Scheduling Developer Profile
10 plugins · 20K total installs
How We Detect Timetics – Appointment Booking & Scheduling
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/timetics/assets/css/backend.css/wp-content/plugins/timetics/assets/css/frontend.css/wp-content/plugins/timetics/assets/js/backend.js/wp-content/plugins/timetics/assets/js/frontend.jstimetics/assets/css/backend.css?ver=timetics/assets/css/frontend.css?ver=timetics/assets/js/backend.js?ver=timetics/assets/js/frontend.js?ver=HTML / DOM Fingerprints
timetics-booking-calendartimetics-appointments-wrapTimetics Essential is distributed in the hope that it will be usefulTimetics is free software: you can redistribute it and/or modifydata-timetics-bookingdata-timetics-appointment-idtimeticsApptimetics/timetics/v1/feedback[timetics_booking_form][timetics_calendar]