
Holy Day Off Security & Risk Analysis
wordpress.org/plugins/holy-day-offThe #1 Shabbat & Jewish holiday plugin for WordPress. Automatically close your WooCommerce store on schedule. Set your city once, rest every week.
Is Holy Day Off Safe to Use in 2026?
Generally Safe
Score 100/100Holy Day Off has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "holy-day-off" plugin v1.2.4 presents a generally positive security posture based on the provided static analysis. The absence of any known CVEs, critical taint flows, or identified entry points without authentication checks is a strong indicator of good development practices. The plugin also demonstrates a high percentage of properly escaped output, which is crucial for preventing cross-site scripting (XSS) vulnerabilities. The limited use of file operations and external HTTP requests also contributes to a reduced attack surface.
However, several areas warrant attention. The presence of one cron event without explicit mention of authentication or capability checks suggests a potential, albeit small, risk. Furthermore, the single SQL query is not utilizing prepared statements, which is a significant concern for preventing SQL injection vulnerabilities. The lack of nonce checks and capability checks across the board also raises red flags, especially if any of the identified entry points (even if currently zero) were to evolve in future versions. The inclusion of the Select2 library, while common, could pose a risk if it's an older, unpatched version, though this is not explicitly detailed in the provided data.
In conclusion, the "holy-day-off" plugin shows strengths in its low attack surface and output escaping. The absence of historical vulnerabilities is reassuring. However, the lack of prepared statements for its SQL query and the potential for unprotected cron events are notable weaknesses that require remediation to ensure a more robust security profile.
Key Concerns
- Raw SQL query without prepared statements
- Missing capability checks
- Missing nonce checks
- Potential unprotected cron event
Holy Day Off Security Vulnerabilities
Holy Day Off Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Holy Day Off Attack Surface
WordPress Hooks 18
Scheduled Events 1
Maintenance & Trust
Holy Day Off Maintenance & Trust
Maintenance Signals
Community Trust
Holy Day Off Alternatives
Store Vacation for WooCommerce
woo-store-vacation
Take a break from selling by putting your WooCommerce shop on hold with vacation mode. Keep customers informed during vacations and holidays.
Holiday Mode for WooCommerce
holiday-mode-for-woocommerce
Set your WooCommerce® shop to holiday/vacation mode. Use date range to schedule closed time.
Holiday for WooCommerce
wc-holiday
Adds a link to your WooCommerce menu "Holiday for WooCommerce" which allows you to disable the WooCommerce purchasing options but keep the p …
WP-Shabbat
wp-shabbat
Close site or display popup message on Shabbat and Holidays by identifying the address of the user IP and close to 40 km
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Holy Day Off Developer Profile
1 plugin · 10 total installs
How We Detect Holy Day Off
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/holy-day-off/assets/style.css/wp-content/plugins/holy-day-off/assets/select2.min.css/wp-content/plugins/holy-day-off/assets/select2.min.js/wp-content/plugins/holy-day-off/assets/script.jsholy-day-off/assets/style.css?ver=holy-day-off/assets/select2.min.css?ver=holy-day-off/assets/select2.min.js?ver=holy-day-off/assets/script.js?ver=