
CalJ Shabbat Times Security & Risk Analysis
wordpress.org/plugins/caljDisplay the Shabbat times (zmanim) for the city of your choice.
Is CalJ Shabbat Times Safe to Use in 2026?
Mostly Safe
Score 78/100CalJ Shabbat Times is generally safe to use. 1 past CVE were resolved.
The plugin "calj" v1.5 exhibits a generally positive security posture, with several good practices observed. Notably, it has a small attack surface, with only one entry point (a shortcode) and no AJAX handlers, REST API routes, or cron events. All SQL queries are properly prepared, and there are no file operations or external HTTP requests that appear to be directly controllable by user input. The absence of known vulnerabilities in its history is also a strong indicator of good development and maintenance.
However, there are significant areas for improvement and concern. The most pressing issue is the lack of output escaping, with only 20% of outputs being properly handled. This leaves the plugin vulnerable to Cross-Site Scripting (XSS) attacks, especially given the presence of taint flows with unsanitized paths. The absence of nonce and capability checks further exacerbates this risk, as it suggests that the plugin may not be adequately protecting sensitive actions or data from unauthorized access or manipulation. While the attack surface is small, the lack of proper sanitization and authorization on the identified flows represents a critical weakness.
In conclusion, while "calj" v1.5 benefits from a limited attack surface and secure SQL handling, the critical vulnerabilities in output escaping and the lack of authorization checks present a significant risk. The presence of unsanitized taint flows, coupled with these weaknesses, means that despite its clean vulnerability history, the plugin requires immediate attention to mitigate potential XSS and privilege escalation attacks.
Key Concerns
- Unsanitized taint flows detected
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
CalJ Shabbat Times Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
CalJ <= 1.5 - Authenticated (Subscriber+) Arbitrary Settings Modification via 'save-obtained-key' Action
CalJ Shabbat Times Release Timeline
CalJ Shabbat Times Code Analysis
Output Escaping
Data Flow Analysis
CalJ Shabbat Times Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
CalJ Shabbat Times Maintenance & Trust
Maintenance Signals
Community Trust
CalJ Shabbat Times Alternatives
HB Jewish Calendar
hb-jewish-calendar
Display Hebrew dates, Parasha, zmanim and an interactive monthly Hebrew calendar via shortcodes and Elementor widgets.
Shortcode for Current Date
shortcode-for-current-date
Insert current Date, Month or Year anywhere in your WordPress site with a simple shortcode.
WP Date and Time Shortcode
wp-date-and-time-shortcode
Shortcode to show any current, past, and future date or time. Display this, previous, or next year, month, day, etc.
Dynamic Month & Year into Posts
dynamic-month-year-into-posts
Automate SEO and content with dynamic shortcodes for dates, years, months, age calculations, seasons and countdowns in content, titles and meta.
Current Date Shortcode For WordPess
current-date
Easily display the current date anywhere using a simple shortcode, Gutenberg block, Elementor addon
CalJ Shabbat Times Developer Profile
1 plugin · 80 total installs
How We Detect CalJ Shabbat Times
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
calj.php?ver=calj.css?ver=calj.js?ver=HTML / DOM Fingerprints
caljshabbat[ERR:-