WPC Countdown Timer for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wpc-countdown-timer

WPC Countdown Timer helps you display countdown timer in single product pages and shop page.

1K active installs v3.1.8 PHP + WP 4.0+ Updated Mar 26, 2026
clockcountdowntimerwoocommercewpc
99
A · Safe
CVEs total1
Unpatched0
Last CVEOct 20, 2025
Safety Verdict

Is WPC Countdown Timer for WooCommerce Safe to Use in 2026?

Generally Safe

Score 99/100

WPC Countdown Timer for WooCommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Oct 20, 2025Updated 1mo ago
Risk Assessment

This plugin exhibits a generally strong security posture, with a significant number of protective measures in place. The absence of unprotected entry points, 100% use of prepared statements for SQL queries, and a substantial number of nonce and capability checks are all positive indicators. Furthermore, the taint analysis revealed no critical or high severity issues, suggesting a good effort in sanitizing user inputs. However, the presence of the `unserialize` function three times is a notable concern. While not explicitly flagged as a vulnerability in the static analysis or taint flow, `unserialize` is notoriously prone to security issues if not handled with extreme care, especially when dealing with untrusted data. The plugin's vulnerability history shows one medium severity CVE related to Cross-Site Scripting, which, although currently patched, highlights a past susceptibility to input manipulation. Overall, the plugin is well-defended against common attack vectors, but the `unserialize` usage warrants careful review and potential mitigation to further strengthen its security.

Key Concerns

  • Presence of 'unserialize' function
  • Past medium severity XSS vulnerability
Vulnerabilities
1 published

WPC Countdown Timer for WooCommerce Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-49908medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WPC Countdown Timer for WooCommerce <= 3.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 20, 2025 Patched in 3.1.5 (10d)
Version History

WPC Countdown Timer for WooCommerce Release Timeline

v3.1.8Current
v3.1.7
v3.1.6
v3.1.5
v3.1.41 CVE
v3.1.31 CVE
v3.1.21 CVE
v3.1.11 CVE
v3.1.01 CVE
v3.0.91 CVE
v3.0.81 CVE
v3.0.71 CVE
v3.0.61 CVE
v3.0.51 CVE
v3.0.41 CVE
v3.0.31 CVE
v3.0.21 CVE
v3.0.11 CVE
v3.0.01 CVE
v2.6.51 CVE
Code Analysis
Analyzed Mar 16, 2026

WPC Countdown Timer for WooCommerce Code Analysis

Dangerous Functions
3
Raw SQL Queries
0
0 prepared
Unescaped Output
55
188 escaped
Nonce Checks
8
Capability Checks
2
File Operations
0
External Requests
3
Bundled Libraries
0

Dangerous Functions Found

unserialize$plugins = unserialize( $response['body'] );includes\dashboard\wpc-dashboard.php:111
unserialize$plugins = unserialize( $response['body'] );includes\dashboard\wpc-dashboard.php:189
unserialize$plugins = unserialize( $response['body'] );includes\kit\wpc-kit.php:98

Output Escaping

77% escaped243 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

6 flows
ajax_export (includes\dashboard\wpc-dashboard.php:225)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WPC Countdown Timer for WooCommerce Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 6

authwp_ajax_wpc_get_pluginsincludes\dashboard\wpc-dashboard.php:19
authwp_ajax_wpc_get_suggestionincludes\dashboard\wpc-dashboard.php:20
authwp_ajax_wpc_exportincludes\dashboard\wpc-dashboard.php:21
authwp_ajax_wpc_importincludes\dashboard\wpc-dashboard.php:22
authwp_ajax_wpc_get_essential_kitincludes\kit\wpc-kit.php:22
authwp_ajax_wooct_previewwpc-countdown-timer.php:137

Shortcodes 1

[wooct_product] wpc-countdown-timer.php:134
WordPress Hooks 31
actionadmin_enqueue_scriptsincludes\dashboard\wpc-dashboard.php:17
actionadmin_menuincludes\dashboard\wpc-dashboard.php:18
actionbefore_woocommerce_initincludes\hpos.php:7
actionadmin_enqueue_scriptsincludes\kit\wpc-kit.php:20
actionadmin_menuincludes\kit\wpc-kit.php:21
actionplugins_loadedwpc-countdown-timer.php:38
actionadmin_noticeswpc-countdown-timer.php:42
actioninitwpc-countdown-timer.php:66
actionadmin_initwpc-countdown-timer.php:69
actionadmin_menuwpc-countdown-timer.php:70
actionwp_enqueue_scriptswpc-countdown-timer.php:73
actionadmin_enqueue_scriptswpc-countdown-timer.php:76
filterplugin_action_linkswpc-countdown-timer.php:79
filterplugin_row_metawpc-countdown-timer.php:80
filterwoocommerce_product_data_tabswpc-countdown-timer.php:83
actionwoocommerce_product_data_panelswpc-countdown-timer.php:84
actionwoocommerce_process_product_metawpc-countdown-timer.php:85
actionwoocommerce_product_after_variable_attributeswpc-countdown-timer.php:88
actionwoocommerce_save_product_variationwpc-countdown-timer.php:92
actionwoocommerce_after_variations_tablewpc-countdown-timer.php:93
filtermanage_edit-product_columnswpc-countdown-timer.php:96
actionmanage_product_posts_custom_columnwpc-countdown-timer.php:97
filterwoocommerce_post_classwpc-countdown-timer.php:100
actionwoocommerce_shop_loop_item_titlewpc-countdown-timer.php:107
actionwoocommerce_after_shop_loop_item_titlewpc-countdown-timer.php:110
actionwoocommerce_after_shop_loop_item_titlewpc-countdown-timer.php:113
actionwoocommerce_after_shop_loop_itemwpc-countdown-timer.php:116
actionwoocommerce_after_shop_loop_itemwpc-countdown-timer.php:119
actionwoocommerce_single_product_summarywpc-countdown-timer.php:127
actionwpcvd_duplicatedwpc-countdown-timer.php:140
actionwpcvb_bulk_update_variationwpc-countdown-timer.php:143
Maintenance & Trust

WPC Countdown Timer for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 26, 2026
PHP min version
Downloads65K

Community Trust

Rating100/100
Number of ratings3
Active installs1K
Developer Profile

WPC Countdown Timer for WooCommerce Developer Profile

WPClever

73 plugins · 441K total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
76 days
View full developer profile
Detection Fingerprints

How We Detect WPC Countdown Timer for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wpc-countdown-timer/includes/wpc-countdown-timer.css/wp-content/plugins/wpc-countdown-timer/assets/js/wooct-admin.js/wp-content/plugins/wpc-countdown-timer/assets/js/wooct-frontend.js
Script Paths
/wp-content/plugins/wpc-countdown-timer/assets/js/wooct-admin.js/wp-content/plugins/wpc-countdown-timer/assets/js/wooct-frontend.js
Version Parameters
wpc-countdown-timer/includes/wpc-countdown-timer.css?ver=wpc-countdown-timer/assets/js/wooct-admin.js?ver=wpc-countdown-timer/assets/js/wooct-frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
wpc-countdown-timer-product-wrapwooct-countdown-single
HTML Comments
<!-- WPClever Countdown Timer -->
Data Attributes
data-wooct-countdown
JS Globals
wooct_params
Shortcode Output
[wooct_product
FAQ

Frequently Asked Questions about WPC Countdown Timer for WooCommerce