WP TimeZone Security & Risk Analysis

wordpress.org/plugins/wp-timezone

Takes care of publishing posts that missed their schedule, for CET/CEST time zones only.

200 active installs v1.3 PHP + WP 3.1+ Updated Aug 17, 2015
daylight-savingtimetime-zonetimezonezone
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP TimeZone Safe to Use in 2026?

Generally Safe

Score 85/100

WP TimeZone has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the wp-timezone v1.3 plugin exhibits a strong security posture. The static analysis reveals a completely clean attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and importantly, none of these entry points are unprotected. The code also demonstrates excellent security practices with no dangerous functions, all SQL queries utilizing prepared statements, and 100% of output being properly escaped. There are no file operations or external HTTP requests, further reducing potential attack vectors. The absence of any taint analysis findings, including unsanitized paths or critical/high severity flows, is a significant positive indicator. The plugin's vulnerability history is equally impressive, with zero recorded CVEs of any severity, suggesting a well-maintained and secure codebase over its development lifecycle. The lack of any common vulnerability types or recent issues reinforces this. The primary strength lies in the minimal attack surface and the robust coding practices observed. While the absence of nonce and capability checks on entry points is technically noted, the complete lack of entry points renders this a non-issue in practice for this specific version. Overall, wp-timezone v1.3 appears to be a highly secure plugin.

Vulnerabilities
None known

WP TimeZone Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP TimeZone Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries
Attack Surface

WP TimeZone Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actioninitwp-timezone.php:41
actionplugins_loadedwp-timezone.php:42
filtergettextwp-timezone.php:44
filterplugin_row_metawp-timezone.php:45
Maintenance & Trust

WP TimeZone Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedAug 17, 2015
PHP min version
Downloads6K

Community Trust

Rating60/100
Number of ratings2
Active installs200
Developer Profile

WP TimeZone Developer Profile

ezraverheijen

4 plugins · 11K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP TimeZone

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-timezone/css/wp-timezone.css
Script Paths
/wp-content/plugins/wp-timezone/js/wp-timezone.js
Version Parameters
wp-timezone/css/wp-timezone.css?ver=wp-timezone/js/wp-timezone.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about WP TimeZone