
Bitkit Opening Hours & Holidays Security & Risk Analysis
wordpress.org/plugins/bitkit-opening-hours-holidaysManage and display business opening hours, holidays and vacation periods with shortcodes, a Gutenberg block, a widget and JSON-LD structured data.
Is Bitkit Opening Hours & Holidays Safe to Use in 2026?
Generally Safe
Score 100/100Bitkit Opening Hours & Holidays has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bitkit-opening-hours-holidays" plugin v1.0.1 demonstrates a generally good security posture with no known vulnerabilities or critical issues identified in the provided data. The plugin adheres to several security best practices, including the absence of dangerous functions and all SQL queries utilizing prepared statements. It also performs nonce checks and capability checks, indicating an effort to protect against common WordPress exploits. The limited attack surface with zero unprotected entry points is a significant strength.
However, the static analysis did reveal a potential concern with unsanitized paths identified in the taint analysis. While no critical or high severity issues were found, this single unsanitized path warrants attention as it could potentially be exploited under specific circumstances, though its exploitability is not confirmed as high. The high percentage of properly escaped output (73%) is a positive sign, but it also implies that 27% of outputs are not properly escaped, which could lead to XSS vulnerabilities if user-supplied data is involved in these unescaped outputs.
Given the lack of historical vulnerabilities, the plugin appears to be maintained with security in mind. The strengths lie in its low attack surface, use of prepared statements, and basic security checks. The weaknesses are primarily related to the potential for an unsanitized path and a notable percentage of unescaped output. Overall, the plugin appears relatively safe, but the identified taint flow and unescaped outputs suggest areas for improvement to achieve a more robust security profile.
Key Concerns
- Flows with unsanitized paths
- Unescaped output (27% of total)
Bitkit Opening Hours & Holidays Security Vulnerabilities
Bitkit Opening Hours & Holidays Code Analysis
Output Escaping
Data Flow Analysis
Bitkit Opening Hours & Holidays Attack Surface
WordPress Hooks 17
Maintenance & Trust
Bitkit Opening Hours & Holidays Maintenance & Trust
Maintenance Signals
Community Trust
Bitkit Opening Hours & Holidays Alternatives
SiteOrigin Widgets Bundle
so-widgets-bundle
Essential elements for modern websites. Add buttons, sliders, heroes, maps, images, carousels, features, icons, more. Create dynamic pages easily.
Widget Logic
widget-logic
Widget Logic lets you control on which pages widgets appear using WP's conditional tags.
Widget Options – Advanced Conditional Visibility for Gutenberg Blocks & Classic Widgets
widget-options
0ddcemmihs4a843ekhaoofzosrunf4bl Widget Options gives you super powers to control your site’s sidebar widgets and all Gutenberg blocks on pages, posts …
Spotlight Social Feeds – Block, Shortcode, and Widget
spotlight-social-photo-feeds
Instagram feeds made easy. Responsive, customizable, accessible, and SEO-friendly out of the box. Includes Instagram blocks & oEmbed support.
WDesignKit – Elementor & Gutenberg Starter Templates, Patterns, Cloud Workspace & Widget Builder
wdesignkit
3000+ Elementor Templates, Gutenberg Templates, Widgets Builder for Elementor, Gutenberg & Bricks, Cloud Workspace & Figma Files, 160+ Widgets Library
Bitkit Opening Hours & Holidays Developer Profile
1 plugin · 10 total installs
How We Detect Bitkit Opening Hours & Holidays
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bitkit-opening-hours-holidays/assets/admin/admin.css/wp-content/plugins/bitkit-opening-hours-holidays/assets/admin/admin.js/wp-content/plugins/bitkit-opening-hours-holidays/assets/admin/admin.jsbitkit-opening-hours-holidays/assets/admin/admin.css?ver=bitkit-opening-hours-holidays/assets/admin/admin.js?ver=bitkit-opening-hours-holidays/assets/icons/material-symbols.css?ver=HTML / DOM Fingerprints
data-nonce="bkohh_admin"BKOHH_ADMIN