
ZYX Classical Circular Clock Security & Risk Analysis
wordpress.org/plugins/zyx-classical-circular-clockA simple and configurable Flash clock. There is a widget, a shortcode and a template tag.
Is ZYX Classical Circular Clock Safe to Use in 2026?
Generally Safe
Score 85/100ZYX Classical Circular Clock has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'zyx-classical-circular-clock' plugin v0.9 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no raw SQL queries, and no file operations or external HTTP requests, all of which are strong indicators of good development practices. The complete absence of known CVEs and a clean vulnerability history further contribute to a perception of a relatively secure plugin. However, there are significant concerns. The low percentage of properly escaped output (5%) is a major red flag, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the lack of nonce checks and capability checks on any entry points means that even the single shortcode could potentially be abused if it leads to any sensitive operations or output that is not properly sanitized, although the static analysis didn't directly flag specific vulnerabilities related to this. The absence of taint analysis results is also notable, as it prevents a deeper understanding of how data flows within the plugin and if malicious input could be processed unsafely. While the plugin avoids common pitfalls like raw SQL and dangerous functions, the poor output escaping and lack of robust authentication/authorization checks on its sole entry point are critical weaknesses that need immediate attention.
Key Concerns
- Low output escaping percentage
- No nonce checks on entry points
- No capability checks on entry points
ZYX Classical Circular Clock Security Vulnerabilities
ZYX Classical Circular Clock Code Analysis
Output Escaping
ZYX Classical Circular Clock Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
ZYX Classical Circular Clock Maintenance & Trust
Maintenance Signals
Community Trust
ZYX Classical Circular Clock Alternatives
Local Time Clock
local-time-clock
Display a clock on your sidebar set automatically to your location's timezone. Select from a choice of clocks, colors and sizes.
World Clock
flash-world-clock
World clock showing the local time at six major cities round the world. The plugin provides a choice of analog and digital clocks, colors and sizes.
Xorbin Analog Flash Clock
xorbin-analog-flash-clock
Customizable Analog Clock plugin by XorBin.com
Analog Clock Widget
analog-clock-widget
Analog Clock Widget plugin allows you to create an unlimited number of different analog clocks. The plugin based on SVG Raphael - JavaScript Library.
New Year Countdown Clock
new-year-countdown-clock
New Year countdown clock showing days and hours until New Year day. Select from several designs, sizes, animations and backgrounds
ZYX Classical Circular Clock Developer Profile
1 plugin · 10 total installs
How We Detect ZYX Classical Circular Clock
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zyx-classical-circular-clock/js/zyx-analog-clock.js/wp-content/plugins/zyx-classical-circular-clock/css/zyx-analog-clock.css/wp-content/plugins/zyx-classical-circular-clock/js/zyx-analog-clock.jszyx-classical-circular-clock/js/zyx-analog-clock.js?ver=zyx-classical-circular-clock/css/zyx-analog-clock.css?ver=HTML / DOM Fingerprints
[analog_clock