
Kırk Hadis Security & Risk Analysis
wordpress.org/plugins/kirk-hadisBu eklenti, Türkiye Cumhuriyeti Diyanet İşleri Başkanlığı resmi internet sitesinden alınan 40 hadisi, rastgele bir şekilde ziyaretçilerinize göstermek …
Is Kırk Hadis Safe to Use in 2026?
Generally Safe
Score 85/100Kırk Hadis has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'kirk-hadis' plugin v1.0 exhibits a strong security posture in several key areas. The static analysis reveals no identified attack surface, meaning there are no exposed AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code signals indicate a complete absence of dangerous functions and external HTTP requests. The plugin also demonstrates good practice by using prepared statements for all its SQL queries and has no file operations or bundled libraries to consider for outdated versions. This suggests a well-contained and potentially secure plugin architecture.
However, a significant concern arises from the lack of output escaping, with 0% of the 4 identified outputs being properly escaped. This represents a potential vulnerability to cross-site scripting (XSS) attacks, where malicious scripts could be injected into the plugin's output and executed in a user's browser. The absence of nonce checks and capability checks, coupled with no identified authentication checks on entry points, further amplifies this risk. The taint analysis showing zero flows is positive but might be limited by the absence of detected entry points.
With no known vulnerability history, this plugin has a clean track record. However, the static analysis findings, particularly the unescaped output and lack of authorization checks on hypothetical future entry points, highlight areas that require immediate attention. The plugin's strengths lie in its contained nature and secure database interactions, but the identified output sanitation and authorization gaps present a notable risk that needs to be addressed to achieve a truly secure state.
Key Concerns
- Unescaped output
- Missing nonce checks
- Missing capability checks
Kırk Hadis Security Vulnerabilities
Kırk Hadis Code Analysis
Output Escaping
Kırk Hadis Attack Surface
WordPress Hooks 1
Maintenance & Trust
Kırk Hadis Maintenance & Trust
Maintenance Signals
Community Trust
Kırk Hadis Alternatives
Landing Page Cat – Coming Soon & Maintenance Pages
landing-page-cat
Landing Page Cat Lets You Publish A Beautiful Coming Soon Page, Maintenance Page or Squeeze Page For WordPress, In Just 2 Minutes.
AS login
as-login
AS login you can fully customize wordpress login page.
Elementor Website Builder – More Than Just a Page Builder
elementor
The Elementor Website Builder has it all: drag and drop page builder, pixel perfect design, mobile responsive editing, and more. Get started now!
Redirection
redirection
Manage 301 redirects, track 404 errors, and improve your site. No knowledge of Apache or Nginx required.
Website Builder by SeedProd — Theme Builder, Landing Page Builder, Coming Soon Page, Maintenance Mode
coming-soon
Easy Drag & Drop Page Builder. A complete solution to create a WordPress Website, Custom Themes, Landing Pages, Coming Soon & Maintenance Mode Pages.
Kırk Hadis Developer Profile
8 plugins · 90 total installs
How We Detect Kırk Hadis
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kirk-hadis/kh-widget.css/wp-content/plugins/kirk-hadis/kh-widget.js/wp-content/plugins/kirk-hadis/kh-widget.jskirk-hadis/kh-widget.css?ver=kirk-hadis/kh-widget.js?ver=HTML / DOM Fingerprints
kh_widget