
World Clocks Security & Risk Analysis
wordpress.org/plugins/world-clocksEnable world clocks for the sites with different timezones, with a custom block for the WordPress block editor (Gutenberg).
Is World Clocks Safe to Use in 2026?
Generally Safe
Score 100/100World Clocks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "world-clocks" plugin version 1.0.3 presents a generally positive security posture based on the static analysis. The plugin demonstrates good practices by not exposing any AJAX handlers, REST API routes, shortcodes, or cron events, thereby minimizing its attack surface significantly. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests, combined with a high percentage of properly escaped output and 100% usage of prepared statements for SQL queries, indicates a cautious approach to coding. The plugin also appears to have no known vulnerabilities in its history, which is a strong indicator of its current security state.
However, the analysis does reveal some areas that warrant attention. The complete absence of nonce checks and capability checks across all entry points is a significant concern. While the attack surface is currently zero, if any entry points were to be introduced in the future, they would be inherently unprotected. The taint analysis showing zero flows, while good, is based on zero flows being analyzed, which might mean limited testing or a very simple plugin. A more robust taint analysis could provide deeper assurance.
In conclusion, the "world-clocks" plugin has a strong foundation with minimal attack surface and good coding practices in place for SQL and output handling. The lack of historical vulnerabilities is also a positive sign. The primary weakness lies in the complete absence of authentication and authorization checks (nonces and capabilities), which, while not posing an immediate threat due to the current lack of entry points, represents a latent risk should the plugin evolve. The plugin is recommended for continued monitoring, but the current risks appear to be low, provided no new entry points are added without proper security measures.
Key Concerns
- No Nonce Checks on Entry Points
- No Capability Checks on Entry Points
- Taint Analysis: 0 flows analyzed
World Clocks Security Vulnerabilities
World Clocks Code Analysis
Output Escaping
World Clocks Attack Surface
WordPress Hooks 3
Maintenance & Trust
World Clocks Maintenance & Trust
Maintenance Signals
Community Trust
World Clocks Alternatives
World Clock
flash-world-clock
World clock showing the local time at six major cities round the world. The plugin provides a choice of analog and digital clocks, colors and sizes.
jClocksGMT World Clocks
jclocksgmt-wp
jQuery based analog and digital world clocks for Wordpress.
Analog Clock display Widget
analog-clock-display-widget
This is a analog clock plugin. It's use for preview analog clock in widget area.
Display Time(zone)
display-timezone
Display Timezone is simple plug-in to display current time with timezone in the upper right of your admin screen on every page.
GNTT Timezone Clock
gntt-timezone-clock
This plugin will make a display of a live clock in your posts, pages and widget text with your location's timezone. plugin url:'http://marke …
World Clocks Developer Profile
4 plugins · 160 total installs
How We Detect World Clocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/world-clocks/dist/admin-style.cssworld-clocks/dist/admin-style.css?ver=HTML / DOM Fingerprints
SPWPCLOCK