
Hijri Calendar Security & Risk Analysis
wordpress.org/plugins/hijri-calendarEasily display current Hijri/Islamic date (according to hijri calendar), anywhere in your wordpress blog!
Is Hijri Calendar Safe to Use in 2026?
Generally Safe
Score 85/100Hijri Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "hijri-calendar" v3.0 plugin exhibits a generally good security posture with some notable areas of concern. The plugin demonstrates strong adherence to secure coding practices by exclusively using prepared statements for all SQL queries and having no recorded vulnerability history, suggesting a history of responsible development and maintenance. Furthermore, the limited attack surface of 2 shortcodes, with no identified unprotected entry points, is positive. However, the static analysis reveals a significant weakness in output escaping, with only 3% of outputs being properly escaped. This, coupled with the presence of two "flows with unsanitized paths" from the taint analysis, presents a risk of Cross-Site Scripting (XSS) vulnerabilities. While no critical or high severity taint flows were identified, the unsanitized paths indicate potential injection vectors that could be exploited if user-supplied data is not meticulously handled before being rendered in the output.
Key Concerns
- Low percentage of properly escaped outputs
- Unsanitized paths in taint analysis
Hijri Calendar Security Vulnerabilities
Hijri Calendar Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Hijri Calendar Attack Surface
Shortcodes 2
WordPress Hooks 2
Maintenance & Trust
Hijri Calendar Maintenance & Trust
Maintenance Signals
Community Trust
Hijri Calendar Alternatives
Hijri Calendar Developer Profile
5 plugins · 7K total installs
How We Detect Hijri Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[en_hijri_calendar][en_hijri_date]