
AZAN Plugin Security & Risk Analysis
wordpress.org/plugins/azanDisplay prayer times by widget.
Is AZAN Plugin Safe to Use in 2026?
Generally Safe
Score 91/100AZAN Plugin has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'azan' plugin v0.7 exhibits a mixed security posture. On one hand, the static analysis indicates a strong adherence to secure coding practices in several areas. The complete absence of dangerous functions, file operations, and external HTTP requests, along with 100% of SQL queries utilizing prepared statements, are significant strengths. Furthermore, the presence of a nonce check is a positive sign. However, the very low percentage of properly escaped output (23%) represents a substantial concern, leaving the plugin vulnerable to various cross-site scripting (XSS) attacks.
The lack of identified taint flows and unprotected entry points (AJAX, REST API, shortcodes, cron) is encouraging, suggesting the core functionality is not immediately exposed to direct attacks. The vulnerability history, while showing one past medium-severity CSRF vulnerability, is also positive in that it is currently unpatched. This indicates that past issues have been addressed or are no longer present in this version. The primary weakness lies in the output escaping, which needs immediate attention to prevent potential client-side compromises.
In conclusion, 'azan' v0.7 has a good foundation with secure handling of data operations and a limited attack surface. The absence of critical and high-severity issues in the taint analysis and vulnerability history further bolsters its security. However, the critical deficiency in output escaping introduces a significant risk that overshadows its strengths. Remediation of the output escaping is paramount to improving the plugin's overall security.
Key Concerns
- Low output escaping percentage
- Past medium vulnerability (CSRF)
AZAN Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
AZAN Plugin <= 0.6 - Cross-Site Request Forgery to Stored Cross-Site Scripting
AZAN Plugin Release Timeline
AZAN Plugin Code Analysis
Output Escaping
AZAN Plugin Attack Surface
WordPress Hooks 6
Maintenance & Trust
AZAN Plugin Maintenance & Trust
Maintenance Signals
Community Trust
AZAN Plugin Alternatives
ووکامرس فارسی
persian-woocommerce
بسته ووکامرس فارسی به راحتی سیستم فروشگاه ساز ووکامرس را فارسی می کند و امکانات جدید متناسب با ایران را به ووکامرس اضافه میکند.
پارسی دیت – Parsi Date
wp-parsidate
Persian date support for WordPress
المنتور فارسی
persian-elementor
بسته کامل فارسیساز المنتور با 13 فونت ایرانی، ترجمه المنتور و المنتور پرو، آیکونهای ایرانی، تقویم شمسی، ویجتهای نقشه نشان و آپارات.
افزونه پیامک ووکامرس Persian WooCommerce SMS
persian-woocommerce-sms
افزونه کامل و حرفه ای برای اطلاع رسانی پیامکی سفارشات و رویداد های محصولات ووکامرس
wp-jalali
wp-jalali
Full Jalali calendar support for Wordpress and localization improvements for Persian/Afghan/Tajik users.
AZAN Plugin Developer Profile
7 plugins · 8K total installs
How We Detect AZAN Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/azan/azan.css/wp-content/plugins/azan/azan.js/wp-content/plugins/azan/azan.jsazan/azan.css?ver=azan/azan.js?ver=HTML / DOM Fingerprints
widget_azandata-azan-citydata-azan-offsetdata-azan-mode