Muslim Prayer Time-Salah/Iqamah Security & Risk Analysis

wordpress.org/plugins/masjidal

Display the prayer(Athan) and/or Iqamah time for you masjid or location. Use as a widget or use the short codes and format it as you like.

400 active installs v1.8.14 PHP + WP 4.7+ Updated Feb 6, 2025
iqamahislamic-prayer-timesnamaz-timessalah
91
A · Safe
CVEs total1
Unpatched0
Last CVEJan 8, 2025
Download
Safety Verdict

Is Muslim Prayer Time-Salah/Iqamah Safe to Use in 2026?

Generally Safe

Score 91/100

Muslim Prayer Time-Salah/Iqamah has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 8, 2025Updated 1yr ago
Risk Assessment

The "masjidal" plugin v1.8.14 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and has no known unpatched vulnerabilities. The code analysis shows a relatively low number of total entry points, with none identified as being completely unprotected. However, there are areas for concern. The high percentage of outputs that are not properly escaped (15%), coupled with the presence of unsanitized paths in taint flows, suggests a potential for cross-site scripting (XSS) vulnerabilities, even if not currently classified as critical or high severity. The lack of nonce checks on any of its entry points, despite the presence of shortcodes, is a significant oversight. While the plugin has a history of a medium severity XSS vulnerability, the absence of current unpatched issues is a positive sign. Overall, the plugin has strengths in data handling (SQL) and vulnerability management (no unpatched CVEs), but requires attention to output sanitization and input validation, particularly concerning nonce checks to mitigate potential XSS risks.

Key Concerns

  • High percentage of improperly escaped outputs
  • Unsanitized paths in taint analysis flows
  • No nonce checks on entry points
  • Medium severity vulnerability in history
Vulnerabilities
1

Muslim Prayer Time-Salah/Iqamah Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-12515medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Muslim Prayer Time-Salah/Iqamah <= 1.8.11 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 8, 2025 Patched in 1.8.12 (64d)
Code Analysis
Analyzed Mar 16, 2026

Muslim Prayer Time-Salah/Iqamah Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
28
155 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
4
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

85% escaped183 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
mptsi_masjidal_date (includes\function\functions.php:2730)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Muslim Prayer Time-Salah/Iqamah Attack Surface

Entry Points19
Unprotected0

Shortcodes 19

[single_view_calendar] includes\function\functions.php:1996
[masjidal_salah_fajr] includes\function\functions.php:2041
[masjidal_salah_zuhr] includes\function\functions.php:2085
[masjidal_salah_asr] includes\function\functions.php:2124
[masjidal_salah_maghrib] includes\function\functions.php:2167
[masjidal_salah_isha] includes\function\functions.php:2206
[masjidal_iqamah_fajr] includes\function\functions.php:2246
[masjidal_iqamah_zuhr] includes\function\functions.php:2284
[masjidal_iqamah_asr] includes\function\functions.php:2322
[masjidal_iqamah_maghrib] includes\function\functions.php:2365
[masjidal_iqamah_isha] includes\function\functions.php:2403
[masjidal_iqamah_jummah] includes\function\functions.php:2495
[masjidal_salah_sunrise] includes\function\functions.php:2535
[masjidal_salah_sunset] includes\function\functions.php:2575
[masjidal_jummah1] includes\function\functions.php:2618
[masjidal_jummah2] includes\function\functions.php:2660
[masjidal_jummah3] includes\function\functions.php:2685
[masjidal_hijri_date] includes\function\functions.php:2726
[masjidal_today_date] includes\function\functions.php:2756
WordPress Hooks 9
actionadmin_menuincludes\classes\class-Plugin-admin.php:58
actionadmin_menuincludes\classes\class-Plugin-admin.php:59
actionplugins_loadedincludes\classes\classCweb.php:131
actionadmin_enqueue_scriptsincludes\classes\classCweb.php:144
actionadmin_enqueue_scriptsincludes\classes\classCweb.php:145
actionwp_enqueue_stylesincludes\classes\classCweb.php:159
actionwp_enqueue_scriptsincludes\classes\classCweb.php:160
actiontemplate_redirectincludes\function\functions.php:95
actionwidgets_initincludes\function\functions.php:404
Maintenance & Trust

Muslim Prayer Time-Salah/Iqamah Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 6, 2025
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings3
Active installs400
Developer Profile

Muslim Prayer Time-Salah/Iqamah Developer Profile

masjidal

1 plugin · 400 total installs

82
trust score
Avg Security Score
91/100
Avg Patch Time
64 days
View full developer profile
Detection Fingerprints

How We Detect Muslim Prayer Time-Salah/Iqamah

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/masjidal/public/assets/css/components.css/wp-content/plugins/masjidal/admin/css/admin.css
Version Parameters
masjidal/public/assets/css/components.css?ver=

HTML / DOM Fingerprints

CSS Classes
masjidal-prayer-times
Data Attributes
data-masjidal-prayer-times
JS Globals
masjidal_namespace
Shortcode Output
[masjidal_prayer_times][masjidal_monthly_timetable]
FAQ

Frequently Asked Questions about Muslim Prayer Time-Salah/Iqamah