
GoPray Security & Risk Analysis
wordpress.org/plugins/goprayPrayer request application to allow users to submit requests or pray for existing requests
Is GoPray Safe to Use in 2026?
Generally Safe
Score 100/100GoPray has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The gopray plugin v0.3 demonstrates a generally positive security posture, adhering to several good practices. The absence of dangerous functions, file operations, and SQL queries that are not prepared statements are strong indicators of secure coding. Furthermore, the plugin includes a reasonable number of nonce and capability checks for its entry points, and no publicly disclosed vulnerabilities exist.
However, there are areas for improvement. The 75% output escaping rate suggests that a quarter of the plugin's outputs are not properly sanitized, potentially leaving it vulnerable to cross-site scripting (XSS) attacks if user-supplied data is involved in these unescaped outputs. The presence of external HTTP requests, while not inherently a vulnerability, warrants careful review to ensure these requests are made to trusted endpoints and that any data sent or received is handled securely. The static analysis did not identify any taint flows, which is positive, but the lack of comprehensive taint analysis could mean subtle vulnerabilities might be missed.
Overall, gopray v0.3 is in a relatively secure state, especially given its lack of vulnerability history. The primary concern stems from the incomplete output escaping, which requires further investigation. Addressing this would significantly strengthen its security.
Key Concerns
- Incomplete output escaping (25% unescaped)
- External HTTP requests without further context
GoPray Security Vulnerabilities
GoPray Code Analysis
Bundled Libraries
Output Escaping
GoPray Attack Surface
AJAX Handlers 9
Shortcodes 2
WordPress Hooks 33
Maintenance & Trust
GoPray Maintenance & Trust
Maintenance Signals
Community Trust
GoPray Alternatives
GoPrayer
wp-prayers-request
An application that allows an organization share, update, and manage prayer requests.
Church Content – Sermons, Events and More
church-theme-content
Provides an interface for managing sermons, events, people and locations. A compatible theme is required for presenting content from these church-cent …
Daily Prayer Time
daily-prayer-time-for-mosques
Display prayer time in any screen, in any language and many more.
Salat Times
salat-times
Salat (Namaz) timetable for any location around the world!
Muslim Prayer Time-Salah/Iqamah
masjidal
Display the prayer(Athan) and/or Iqamah time for you masjid or location. Use as a widget or use the short codes and format it as you like.
GoPray Developer Profile
3 plugins · 450 total installs
How We Detect GoPray
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gopray/assets/css/admin-style.cssgopray/assets/css/admin-style.css?ver=