
WP Chrono Security & Risk Analysis
wordpress.org/plugins/wp-chronoWP Chrono is plugin that uses simple shortcodes to help you show parts of your pages and posts at specific time and date range(s).
Is WP Chrono Safe to Use in 2026?
Use With Caution
Score 64/100WP Chrono has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "wp-chrono" plugin v1.5.4 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, all SQL queries are prepared, and output is properly escaped. There are also no file operations, external HTTP requests, or bundled libraries, which generally reduces the attack surface. However, the plugin has significant security concerns due to its vulnerability history and unprotected entry points. The presence of one unpatched medium severity CVE (Cross-site Scripting) is a critical red flag, especially since it was recently discovered. Furthermore, the plugin exposes one AJAX handler without any authentication checks, presenting a clear opportunity for attackers to exploit potential vulnerabilities in that specific handler.
Key Concerns
- Unpatched CVE (Medium Severity)
- Unprotected AJAX handler
- Lack of nonce checks (implied by unprotected AJAX)
- Lack of capability checks (implied by unprotected AJAX)
WP Chrono Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Chrono <= 1.5.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Chrono Code Analysis
WP Chrono Attack Surface
AJAX Handlers 1
Shortcodes 4
WordPress Hooks 4
Maintenance & Trust
WP Chrono Maintenance & Trust
Maintenance Signals
Community Trust
WP Chrono Alternatives
Last Modified Timestamp
last-modified-timestamp
Adds the last modified time to the admin interface as well as a [last-modified] shortcode to use on the front-end.
Bulk Datetime Change
bulk-datetime-change
Bulk change date/time for posts.
CC-Server-Time
cc-server-time
This plugin adds a server time to all posts types edit screen.
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
WP Chrono Developer Profile
1 plugin · 50 total installs
How We Detect WP Chrono
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
../public/js/countdowntimer.js../public/js/notice-update.js../public/css/countdowntimer.css/wp-content/plugins/wp-chrono/public/js/countdowntimer.js/wp-content/plugins/wp-chrono/public/js/notice-update.js/wp-content/plugins/wp-chrono/public/css/countdowntimer.css?ver=HTML / DOM Fingerprints
wpch-install-noticewpch_darkbluewpch_bluewpch_darkpurplewpch_purplewpch_greenwpch_lightgreenwpch_red+7 moreid="wpch_clockdiv_id="wpch_clockdivcontent_initializeClock/wp-json/wpch-chrono<div><span class="wpch_days"></span><div class="wpch_smalltext">Days</div></div><div><span class="wpch_hours"></span><div class="wpch_smalltext">Hours</div></div><div><span class="wpch_minutes"></span><div class="wpch_smalltext">Minutes</div></div><div><span class="wpch_seconds"></span><div class="wpch_smalltext">Seconds</div></div><div id="wpch_clockdivcontent_<div class="notice notice-success wpch-install-notice is-dismissible">