Holy Day Off Security & Risk Analysis

wordpress.org/plugins/holy-day-off

The #1 Shabbat & Jewish holiday plugin for WordPress. Automatically close your WooCommerce store on schedule. Set your city once, rest every week.

10 active installs v1.2.4 PHP 7.4+ WP 6.0+ Updated Unknown
close-shopholidayjewish-holidaysshabbatwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Holy Day Off Safe to Use in 2026?

Generally Safe

Score 100/100

Holy Day Off has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "holy-day-off" plugin v1.2.4 presents a generally positive security posture based on the provided static analysis. The absence of any known CVEs, critical taint flows, or identified entry points without authentication checks is a strong indicator of good development practices. The plugin also demonstrates a high percentage of properly escaped output, which is crucial for preventing cross-site scripting (XSS) vulnerabilities. The limited use of file operations and external HTTP requests also contributes to a reduced attack surface.

However, several areas warrant attention. The presence of one cron event without explicit mention of authentication or capability checks suggests a potential, albeit small, risk. Furthermore, the single SQL query is not utilizing prepared statements, which is a significant concern for preventing SQL injection vulnerabilities. The lack of nonce checks and capability checks across the board also raises red flags, especially if any of the identified entry points (even if currently zero) were to evolve in future versions. The inclusion of the Select2 library, while common, could pose a risk if it's an older, unpatched version, though this is not explicitly detailed in the provided data.

In conclusion, the "holy-day-off" plugin shows strengths in its low attack surface and output escaping. The absence of historical vulnerabilities is reassuring. However, the lack of prepared statements for its SQL query and the potential for unprotected cron events are notable weaknesses that require remediation to ensure a more robust security profile.

Key Concerns

  • Raw SQL query without prepared statements
  • Missing capability checks
  • Missing nonce checks
  • Potential unprotected cron event
Vulnerabilities
None known

Holy Day Off Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Holy Day Off Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
10
43 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
5
Bundled Libraries
1

Bundled Libraries

Select2

SQL Query Safety

0% prepared1 total queries

Output Escaping

81% escaped53 total outputs
Attack Surface

Holy Day Off Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actionadmin_menuincludes\Api\SettingsApi.php:23
actionadmin_initincludes\Api\SettingsApi.php:27
actionadmin_enqueue_scriptsincludes\Base\Enqueue.php:12
filtercron_schedulesincludes\Base\Plugin.php:14
actioninitincludes\Base\Plugin.php:21
actionwe_check_shabbat_nextincludes\Base\Plugin.php:22
actionwp_footerincludes\Base\Plugin.php:34
actionwoocommerce_single_product_summaryincludes\Base\Plugin.php:111
actionwoocommerce_after_shop_loop_itemincludes\Base\Plugin.php:113
filterwoocommerce_is_purchasableincludes\Base\Plugin.php:115
filterwoocommerce_add_to_cart_validationincludes\Base\Plugin.php:117
filterwoocommerce_cart_needs_paymentincludes\Base\Plugin.php:122
filterwoocommerce_order_button_htmlincludes\Base\Plugin.php:123
filterwoocommerce_available_payment_gatewaysincludes\Base\Plugin.php:125
actionwoocommerce_check_cart_itemsincludes\Base\Plugin.php:127
actionadmin_noticesincludes\Pages\Admin.php:38
actiontemplate_redirecttemplates\popup.php:2
actionbefore_woocommerce_inittopwp-holy-day-off.php:39

Scheduled Events 1

we_check_shabbat_next
Maintenance & Trust

Holy Day Off Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedUnknown
PHP min version7.4
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Holy Day Off Developer Profile

topwp

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Holy Day Off

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/holy-day-off/assets/style.css/wp-content/plugins/holy-day-off/assets/select2.min.css/wp-content/plugins/holy-day-off/assets/select2.min.js/wp-content/plugins/holy-day-off/assets/script.js
Version Parameters
holy-day-off/assets/style.css?ver=holy-day-off/assets/select2.min.css?ver=holy-day-off/assets/select2.min.js?ver=holy-day-off/assets/script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Holy Day Off