
WP User Timezone Security & Risk Analysis
wordpress.org/plugins/wp-user-timezoneWP User Timezone displays the front-end dates & times in the browser's local timezone without actually modifying your database.
Is WP User Timezone Safe to Use in 2026?
Generally Safe
Score 85/100WP User Timezone has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-user-timezone" v1.0.2 plugin exhibits a mixed security posture. On the positive side, it has no known CVEs, a clean vulnerability history, and all SQL queries are properly prepared, which are excellent indicators of secure coding practices in these areas. The absence of external HTTP requests and file operations further reduces potential attack vectors.
However, there are notable concerns stemming from the static code analysis. A significant portion (68%) of output is not properly escaped. While the attack surface appears small with no unprotected entry points, the lack of nonce checks and capability checks across all entry points is a significant weakness. This means that even though the plugin identifies entry points, it doesn't enforce user authorization or prevent CSRF attacks on these points, leaving them vulnerable to exploitation if any malicious input can be injected.
Given the lack of known vulnerabilities, the plugin might seem safe, but the identified code weaknesses, particularly unescaped output and missing authorization checks, present a real risk of Cross-Site Scripting (XSS) or other injection attacks. The plugin's strengths lie in its SQL handling and lack of external dependencies, but its weaknesses in output sanitization and authorization checks require attention.
Key Concerns
- Significant portion of output unescaped
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
WP User Timezone Security Vulnerabilities
WP User Timezone Code Analysis
Output Escaping
WP User Timezone Attack Surface
Shortcodes 2
WordPress Hooks 13
Maintenance & Trust
WP User Timezone Maintenance & Trust
Maintenance Signals
Community Trust
WP User Timezone Alternatives
Current Date & Time Widget
current-date-time-widget
Provides a widget that shows the current date and time given a specified timezone and format.
WP Server Date Time
wp-server-date-time
This plugin shows the server local current date time & timezone in the upper right of your admin screen on every page.
Date Time Picker for Contact Form 7
date-time-picker-for-contact-form-7
This plugin enables Contact Form 7 text field into a Date picker, Time picker or Date Time picker by using CSS class.
Countdown Timer Ultimate
countdown-timer-ultimate
A quick, easy way to add and display responsive Countdown timer on your website. Also work with Gutenberg shortcode block.
Meks Time Ago
meks-time-ago
Automatically change your post date display to "time ago" format like 1 hour ago, 3 days ago, etc...
WP User Timezone Developer Profile
1 plugin · 10 total installs
How We Detect WP User Timezone
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-user-timezone/public/css/wp-user-timezone-public.css/wp-content/plugins/wp-user-timezone/public/js/wp-user-timezone-public.js/wp-content/plugins/wp-user-timezone/admin/css/wp-user-timezone-admin.css/wp-content/plugins/wp-user-timezone/admin/js/wp-user-timezone-admin.js/wp-content/plugins/wp-user-timezone/public/js/wp-user-timezone-public.js/wp-content/plugins/wp-user-timezone/admin/js/wp-user-timezone-admin.jswp-user-timezone/public/css/wp-user-timezone-public.css?ver=wp-user-timezone/public/js/wp-user-timezone-public.js?ver=wp-user-timezone/admin/css/wp-user-timezone-admin.css?ver=wp-user-timezone/admin/js/wp-user-timezone-admin.js?ver=