
Xorbin Analog Flash Clock Security & Risk Analysis
wordpress.org/plugins/xorbin-analog-flash-clockCustomizable Analog Clock plugin by XorBin.com
Is Xorbin Analog Flash Clock Safe to Use in 2026?
Generally Safe
Score 100/100Xorbin Analog Flash Clock has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The xorbin-analog-flash-clock plugin v1.0.2 exhibits a generally good security posture in several areas. It has a very small attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, all SQL queries are confirmed to use prepared statements, and there are no recorded vulnerabilities or CVEs. This indicates a level of care taken by the developers to avoid common web application vulnerabilities.
However, the static analysis reveals significant concerns regarding output escaping. With 74 total outputs and 0% properly escaped, there's a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data displayed by the plugin could potentially be manipulated to execute malicious scripts in the user's browser. Additionally, the presence of the `create_function` call is a dangerous code signal, as it can lead to code injection if not handled with extreme care, although the lack of taint analysis makes it difficult to assess the exact risk here. The absence of nonce and capability checks further amplifies the risk associated with any potential entry points, though currently, none are exposed.
Overall, while the plugin avoids many common pitfalls and has a clean vulnerability history, the critical deficiency in output escaping and the presence of `create_function` represent substantial security weaknesses. The lack of comprehensive taint analysis leaves potential risks unquantified, but the clear output escaping issue is a direct indicator of exploitable vulnerabilities.
Key Concerns
- 0% of outputs properly escaped
- Dangerous function detected: create_function
- 0 nonce checks
- 0 capability checks
Xorbin Analog Flash Clock Security Vulnerabilities
Xorbin Analog Flash Clock Code Analysis
Dangerous Functions Found
Output Escaping
Xorbin Analog Flash Clock Attack Surface
WordPress Hooks 2
Maintenance & Trust
Xorbin Analog Flash Clock Maintenance & Trust
Maintenance Signals
Community Trust
Xorbin Analog Flash Clock Alternatives
Local Time Clock
local-time-clock
Display a clock on your sidebar set automatically to your location's timezone. Select from a choice of clocks, colors and sizes.
Analog Clock Widget
analog-clock-widget
Analog Clock Widget plugin allows you to create an unlimited number of different analog clocks. The plugin based on SVG Raphael - JavaScript Library.
What Time Is It?
what-time-is-it
A lightweight plugin to display clock widgets on your website.
CoolClock – a Javascript Analog Clock
coolclock
Show an analog clock on your WordPress site sidebar or in post and page content.
Live Clock Widget
wordpress-clock
Display a modern, responsive analog or digital clock using shortcode or widget. No Flash, pure JavaScript.
Xorbin Analog Flash Clock Developer Profile
1 plugin · 80 total installs
How We Detect Xorbin Analog Flash Clock
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/xorbin-analog-flash-clock/media/xorAnalogClock.swf/wp-content/plugins/xorbin-analog-flash-clock/media/expressInstall.swfHTML / DOM Fingerprints
xorAnalogClockWidgetxorClockWidgetxorbinLogoid="xbAnalogClock-name="xbAnalogClock-id="xorClockWidget"class="xorClockWidget"class="xorbinLogo"xbAnalogClock-flashvarsparamsattributesswfobject<div id="xbAnalogClock-<img src="/wp-content/plugins/xorbin-analog-flash-clock/media/analog_clock_by_xorbin.png" />