ZYX Classical Circular Clock Security & Risk Analysis

wordpress.org/plugins/zyx-classical-circular-clock

A simple and configurable Flash clock. There is a widget, a shortcode and a template tag.

10 active installs v0.9 PHP + WP 2.8.0+ Updated Aug 24, 2010
clockflashflash-clocktimewidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ZYX Classical Circular Clock Safe to Use in 2026?

Generally Safe

Score 85/100

ZYX Classical Circular Clock has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The 'zyx-classical-circular-clock' plugin v0.9 exhibits a mixed security posture. On the positive side, the static analysis reveals no dangerous functions, no raw SQL queries, and no file operations or external HTTP requests, all of which are strong indicators of good development practices. The complete absence of known CVEs and a clean vulnerability history further contribute to a perception of a relatively secure plugin. However, there are significant concerns. The low percentage of properly escaped output (5%) is a major red flag, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the lack of nonce checks and capability checks on any entry points means that even the single shortcode could potentially be abused if it leads to any sensitive operations or output that is not properly sanitized, although the static analysis didn't directly flag specific vulnerabilities related to this. The absence of taint analysis results is also notable, as it prevents a deeper understanding of how data flows within the plugin and if malicious input could be processed unsafely. While the plugin avoids common pitfalls like raw SQL and dangerous functions, the poor output escaping and lack of robust authentication/authorization checks on its sole entry point are critical weaknesses that need immediate attention.

Key Concerns

  • Low output escaping percentage
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

ZYX Classical Circular Clock Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ZYX Classical Circular Clock Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
139
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

5% escaped146 total outputs
Attack Surface

ZYX Classical Circular Clock Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[analog_clock] includes\shortcodes.php:19
WordPress Hooks 2
actionwidgets_initincludes\widget.php:261
actioninitzyx-analog-clock.php:20
Maintenance & Trust

ZYX Classical Circular Clock Maintenance & Trust

Maintenance Signals

WordPress version tested2.9.2
Last updatedAug 24, 2010
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

ZYX Classical Circular Clock Developer Profile

Xavier Faraudo i Gener

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ZYX Classical Circular Clock

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zyx-classical-circular-clock/js/zyx-analog-clock.js/wp-content/plugins/zyx-classical-circular-clock/css/zyx-analog-clock.css
Script Paths
/wp-content/plugins/zyx-classical-circular-clock/js/zyx-analog-clock.js
Version Parameters
zyx-classical-circular-clock/js/zyx-analog-clock.js?ver=zyx-classical-circular-clock/css/zyx-analog-clock.css?ver=

HTML / DOM Fingerprints

Shortcode Output
[analog_clock
FAQ

Frequently Asked Questions about ZYX Classical Circular Clock