
Tock Widget Security & Risk Analysis
wordpress.org/plugins/tock-widgetQuickly and easily embed the official Tock booking button and reservation widget into your Wordpress site. The button can be inserted into any page of …
Is Tock Widget Safe to Use in 2026?
Generally Safe
Score 91/100Tock Widget has a strong security track record. Known vulnerabilities have been patched promptly.
The tock-widget plugin v1.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any detected dangerous functions, file operations, or external HTTP requests is commendable. Furthermore, the plugin demonstrates excellent practice by ensuring all SQL queries are prepared and all output is properly escaped. The presence of both nonce and capability checks, even with a small attack surface, indicates an awareness of core WordPress security principles. Taint analysis also shows no concerning flows of unsanitized data, which is a positive indicator.
Despite these strengths, the plugin has a documented history of vulnerabilities, specifically one known CVE attributed to Cross-Site Request Forgery (CSRF). While this CVE is currently unpatched, the fact that there are no currently unpatched vulnerabilities is a good sign. The consistent appearance of CSRF vulnerabilities in its history suggests a recurring weakness that, while addressed in this version, warrants continued vigilance in future development to prevent recurrence. The very small attack surface (zero entry points) means that even a single vulnerability could be significant, but the current analysis suggests a well-mitigated risk for this version.
In conclusion, tock-widget v1.2 appears to be a securely developed plugin with good coding practices. The past vulnerability history, particularly the documented CSRF issues, is the primary area of concern. However, the absence of active, unpatched vulnerabilities and the robust static analysis results indicate that the current version is likely safe to use, provided ongoing security reviews are maintained to address past patterns.
Key Concerns
- Known CVE exists, currently unpatched
Tock Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Tock Widget <= 1.1 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Tock Widget Code Analysis
Output Escaping
Data Flow Analysis
Tock Widget Attack Surface
WordPress Hooks 3
Maintenance & Trust
Tock Widget Maintenance & Trust
Maintenance Signals
Community Trust
Tock Widget Alternatives
in stock products filter widget
in-stock-widget
in stock products filter widget ابزارک فیلتر محصولات موجود
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Tock Widget Developer Profile
1 plugin · 400 total installs
How We Detect Tock Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tock-widget/tock-block.jshttps://www.exploretock.com/tock.jsHTML / DOM Fingerprints
Tock_widget_containerdata-tock-display-modedata-tock-color-modedata-tock-localedata-tock-timezonetocktockBlockVars<div id="Tock_widget_container" data-tock-display-mode="Button" data-tock-color-mode="Blue" data-tock-locale="en-us" data-tock-timezone="America/New_York" style="display:inline-block;"></div>