
World Clock Widget Security & Risk Analysis
wordpress.org/plugins/world-clock-widgetSidebar widget to easy customize and display your date and time of multiple timezones. All settings are available from Sidebar Widget Admin.
Is World Clock Widget Safe to Use in 2026?
Generally Safe
Score 85/100World Clock Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'world-clock-widget' plugin v1.0.0 exhibits a generally good security posture with no known vulnerabilities and a very small attack surface. The static analysis reveals no dangerous functions, no SQL queries that are not prepared, no file operations, and no external HTTP requests. This indicates a commitment to secure coding practices in these critical areas.
However, a significant concern arises from the output escaping. With 18 total outputs and 0% properly escaped, this plugin is highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. Any data displayed by the widget that originates from user input or an external source is likely to be rendered unescaped, allowing attackers to inject malicious scripts. The absence of capability checks and nonce checks, while the attack surface is currently zero, also presents a potential risk if the plugin were to be extended in the future without these security measures being implemented.
Given the lack of vulnerability history, it suggests that this plugin has historically been secure or has not been a target. The current version's primary weakness is the complete lack of output escaping, which is a critical security flaw that overshadows the other positive aspects of its code. Addressing the unescaped output is paramount to improving its security.
Key Concerns
- 0% of outputs are properly escaped
- No capability checks present
- No nonce checks present
World Clock Widget Security Vulnerabilities
World Clock Widget Code Analysis
Output Escaping
World Clock Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
World Clock Widget Maintenance & Trust
Maintenance Signals
Community Trust
World Clock Widget Alternatives
World Clock Dropdown with ShortCodes
world-clock-with-drop-down-shortcodes
A shortcode plugin to display timezone dropdown with digital clock(local time), with hours, minutes & seconds.
CoolClock – a Javascript Analog Clock
coolclock
Show an analog clock on your WordPress site sidebar or in post and page content.
Local Time Clock
local-time-clock
Display a clock on your sidebar set automatically to your location's timezone. Select from a choice of clocks, colors and sizes.
Simple Digital Clock 🕒
simple-digital-clock
It is 🪄 a magical and easy-to-use digital clock with a beautiful UI, supporting multiple languages, locales, dates, captions, and time zones.
Digital Clock
digital-clock
The Digital Clock plugin adds a customizable sidebar clock that auto-adjusts to your timezone. Easy to use, it features dark and light themes.
World Clock Widget Developer Profile
1 plugin · 70 total installs
How We Detect World Clock Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/world-clock-widget/date.js/wp-content/plugins/world-clock-widget/worldclock.js/wp-content/plugins/world-clock-widget/worldclock_control.js/wp-content/plugins/world-clock-widget/date.js/wp-content/plugins/world-clock-widget/worldclock.js/wp-content/plugins/world-clock-widget/worldclock_control.jsworld-clock-widget/style.css?ver=world-clock-widget/script.js?ver=HTML / DOM Fingerprints
id="city0"id="city1"id="city2"id="city3"id="city4"id="city5"+4 moreWorldClock