
Bangla Date and Time Security & Risk Analysis
wordpress.org/plugins/bangla-date-and-timeA simple but useful plugin to display relevant Bangla date, time, calendar and numbers.
Is Bangla Date and Time Safe to Use in 2026?
Generally Safe
Score 85/100Bangla Date and Time has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bangla-date-and-time" v2.6 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any identified attack surface (AJAX, REST API, shortcodes, cron events) is a significant positive, as it limits potential entry points for attackers. Furthermore, the lack of dangerous function calls and file operations also contributes to a reduced risk profile. The taint analysis showing no critical or high severity unsanitized flows is encouraging.
However, there are notable areas of concern. The fact that 100% of the SQL queries are not using prepared statements represents a significant risk for potential SQL injection vulnerabilities. While the plugin has no recorded vulnerability history, this does not negate the inherent risks associated with raw SQL queries. The output escaping, while having a majority of outputs properly escaped, still leaves a portion potentially vulnerable to cross-site scripting (XSS) attacks if any of the unescaped outputs process user-supplied data. The complete absence of nonce and capability checks is also a weakness, especially if any part of the plugin were to be exposed through future development that creates an attack surface.
In conclusion, the "bangla-date-and-time" v2.6 plugin has strengths in its limited attack surface and absence of critical code signals. However, the complete lack of prepared statements for all SQL queries and the absence of security checks like nonces and capabilities are significant vulnerabilities that require immediate attention. The plugin's clean vulnerability history is a positive sign, but it doesn't mitigate the identified coding flaws.
Key Concerns
- All SQL queries use raw queries
- 52% of output escaping is not proper
- 0 Nonce checks
- 0 Capability checks
Bangla Date and Time Security Vulnerabilities
Bangla Date and Time Code Analysis
SQL Query Safety
Output Escaping
Bangla Date and Time Attack Surface
WordPress Hooks 10
Maintenance & Trust
Bangla Date and Time Maintenance & Trust
Maintenance Signals
Community Trust
Bangla Date and Time Alternatives
Bangla Number Converter
bangla-number-converter
Bangla Number Converter plugin will help you to Converts English numbers to Bangla numbers of your WordPress website.
Bangla Calendar Display
bangla-calendar-display
Display the current Bengali (Bangla) date and time on your WordPress site with a choice of attractive layouts. Includes a live preview and shortcode g …
Bangla Number And Month
bangla-number-and-month
Change All Number and Month Name from anywhere of your wordpress into Bangla language.
Bangla Date Display
bangla-date-display
Displays Bangla, Gregorian & Hijri date and Archive Calendar in bangla language via widgets and shortcodes!
Calendar
calendar
A simple but effective Calendar plugin for WordPress that allows you to manage your events and appointments and display them to the world.
Bangla Date and Time Developer Profile
1 plugin · 100 total installs
How We Detect Bangla Date and Time
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bangla-date-and-time/bangla-date-and-time.php