
What Time Is It? Security & Risk Analysis
wordpress.org/plugins/what-time-is-itA lightweight plugin to display clock widgets on your website.
Is What Time Is It? Safe to Use in 2026?
Generally Safe
Score 85/100What Time Is It? has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "what-time-is-it" v1.3 plugin exhibits a generally positive security posture based on the provided static analysis. It demonstrates excellent practices by having no recorded vulnerabilities, SQL queries are exclusively using prepared statements, and there are no detected file operations or external HTTP requests. Furthermore, the plugin has a minimal attack surface with zero identified entry points, which is a significant strength.
However, a notable concern arises from the output escaping. With 54 total outputs and only 11% properly escaped, a significant portion of the plugin's output is not being sanitized. This creates a substantial risk for cross-site scripting (XSS) vulnerabilities, especially since there are no explicit capability checks or nonce checks mentioned. While the lack of a large attack surface mitigates the immediate exploitability, any future introduction of an entry point without proper sanitization or authorization could lead to severe security issues.
In conclusion, the plugin's lack of historical vulnerabilities and secure SQL handling are commendable. Nevertheless, the poor output escaping is a critical weakness that needs immediate attention. The absence of any detected taint flows or dangerous functions is reassuring, but this is likely due to the limited attack surface. The plugin needs to prioritize implementing robust output escaping mechanisms to achieve a truly secure state.
Key Concerns
- Low percentage of properly escaped output
- No capability checks
- No nonce checks
What Time Is It? Security Vulnerabilities
What Time Is It? Code Analysis
Output Escaping
What Time Is It? Attack Surface
WordPress Hooks 3
Maintenance & Trust
What Time Is It? Maintenance & Trust
Maintenance Signals
Community Trust
What Time Is It? Alternatives
Analog Clock Widget
analog-clock-widget
Analog Clock Widget plugin allows you to create an unlimited number of different analog clocks. The plugin based on SVG Raphael - JavaScript Library.
CoolClock – a Javascript Analog Clock
coolclock
Show an analog clock on your WordPress site sidebar or in post and page content.
Local Time Clock
local-time-clock
Display a clock on your sidebar set automatically to your location's timezone. Select from a choice of clocks, colors and sizes.
Digital Clock
digital-clock
The Digital Clock plugin adds a customizable sidebar clock that auto-adjusts to your timezone. Easy to use, it features dark and light themes.
IP2Location World Clock
ip2location-world-clock
Simple world clock widget to display analog or digital clock for multiple time zone on your site. Supported local time, visitor's time and custom …
What Time Is It? Developer Profile
1 plugin · 100 total installs
How We Detect What Time Is It?
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/what-time-is-it/style.cssHTML / DOM Fingerprints
wtii-clock-containerwtii-clock-circlewtii-clock-facewtii-clock-hourwtii-clock-minutewtii-clock-secondwtii-clock-digitaldigiclock-hour+2 more<!-- This is from Idiot Inside's analog clock library --><!-- These lines are from KingKode JSClockGMT Library --><!-- These lines are from both IdiotInside and KingKode --><!-- Generate Clock -->id="hour-id="minute-id="second-id="hour-id="min-id="sec-wtii_wtii_widget_offset_processanalogClockjQuery