Muslim Prayer Time BD – Prayer Reminder for Bangladesh Security & Risk Analysis

wordpress.org/plugins/muslim-prayer-time-bd

A WordPress plugin to display proper prayer times specifically for Bangladeshi Muslims, including prayer reminders, widgets and customizable settings.

200 active installs v3.0.2 PHP 7.4+ WP 5.2+ Updated Mar 4, 2025
islamnamazprayer-timesalatsalat-time
91
A · Safe
CVEs total1
Unpatched0
Last CVEJun 5, 2024
Safety Verdict

Is Muslim Prayer Time BD – Prayer Reminder for Bangladesh Safe to Use in 2026?

Generally Safe

Score 91/100

Muslim Prayer Time BD – Prayer Reminder for Bangladesh has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jun 5, 2024Updated 1yr ago
Risk Assessment

The "muslim-prayer-time-bd" plugin v3.0.2 exhibits a generally good security posture due to its adherence to several WordPress security best practices. The plugin has a limited attack surface with all identified entry points (AJAX handlers and shortcodes) appearing to have proper authentication and capability checks. Its SQL queries are 100% prepared, and a high percentage of outputs are properly escaped, indicating a strong effort to prevent common vulnerabilities. The absence of dangerous functions, file operations, and external HTTP requests further bolsters its security.

However, the taint analysis reveals two flows with unsanitized paths. While these are not rated as critical or high severity, they represent potential avenues for attackers to manipulate file system operations or other path-based actions if exploited in conjunction with other weaknesses or specific server configurations. The plugin's vulnerability history shows one medium-severity CVE, historically a Cross-Site Request Forgery (CSRF), which was addressed. The fact that there are no currently unpatched vulnerabilities is positive, but past CSRF issues suggest that user input handling, especially in forms or actions, might require ongoing vigilance.

In conclusion, the plugin demonstrates a commitment to security by implementing prepared statements, output escaping, and authorization checks. The primary area of concern lies in the identified unsanitized paths from the taint analysis. While not currently critical, these represent a technical risk that should be addressed. The past medium-severity CSRF vulnerability, though patched, serves as a reminder of the importance of robust input validation and CSRF protection.

Key Concerns

  • Taint flows with unsanitized paths
Vulnerabilities
1

Muslim Prayer Time BD – Prayer Reminder for Bangladesh Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-4758medium · 4.3Cross-Site Request Forgery (CSRF)

Muslim Prayer Time BD <= 2.4 - Cross-Site Request Forgery to Settings Reset

Jun 5, 2024 Patched in 2.5 (240d)
Code Analysis
Analyzed Mar 16, 2026

Muslim Prayer Time BD – Prayer Reminder for Bangladesh Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
280 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped296 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
fetch_muslim_prayer_time (actions\mptbd-shortcode.php:84)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Muslim Prayer Time BD – Prayer Reminder for Bangladesh Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_mptbd-district-action-formactions\mptbd-shortcode.php:31
noprivwp_ajax_mptbd-district-action-formactions\mptbd-shortcode.php:33

Shortcodes 1

[prayer_time] actions\mptbd-shortcode.php:28
WordPress Hooks 11
actionwidgets_initactions\mptbd-widget.php:31
actionplugins_loadedinc\init-mptbd.php:29
actionadmin_initinc\init-mptbd.php:32
actionadmin_initinc\init-mptbd.php:35
actionadmin_noticesinc\init-mptbd.php:137
actionwp_enqueue_scriptsinc\mptbd-enqueue.php:27
actionwp_enqueue_scriptsinc\mptbd-enqueue.php:30
actionplugins_loadedmuslim-prayer-time-bd.php:28
actionadmin_enqueue_scriptssettings\mptbd-class.settings-api.php:34
actionadmin_initsettings\mptbd-settings.php:35
actionadmin_menusettings\mptbd-settings.php:38
Maintenance & Trust

Muslim Prayer Time BD – Prayer Reminder for Bangladesh Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 4, 2025
PHP min version7.4
Downloads17K

Community Trust

Rating90/100
Number of ratings8
Active installs200
Developer Profile

Muslim Prayer Time BD – Prayer Reminder for Bangladesh Developer Profile

Realwebcare

9 plugins · 9K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
119 days
View full developer profile
Detection Fingerprints

How We Detect Muslim Prayer Time BD – Prayer Reminder for Bangladesh

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/muslim-prayer-time-bd/assets/css/style.css/wp-content/plugins/muslim-prayer-time-bd/assets/css/widget.css/wp-content/plugins/muslim-prayer-time-bd/assets/js/widget.js/wp-content/plugins/muslim-prayer-time-bd/assets/js/script.js/wp-content/plugins/muslim-prayer-time-bd/admin/css/admin.css
Script Paths
/wp-content/plugins/muslim-prayer-time-bd/assets/js/widget.js/wp-content/plugins/muslim-prayer-time-bd/assets/js/script.js
Version Parameters
muslim-prayer-time-bd/assets/css/style.css?ver=muslim-prayer-time-bd/assets/css/widget.css?ver=muslim-prayer-time-bd/assets/js/widget.js?ver=muslim-prayer-time-bd/assets/js/script.js?ver=muslim-prayer-time-bd/admin/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
mptbd-widget-wrapmptbd-widget-titlemptbd-prayer-timemptbd-prayer-namemptbd-prayer-namesmptbd-prayer-time-namesmptbd-prayer-datemptbd-ramadan-card+7 more
JS Globals
mptbd_ajsmptbd_p_arrmptbd_city_arr
Shortcode Output
[muslim_prayer_time]
FAQ

Frequently Asked Questions about Muslim Prayer Time BD – Prayer Reminder for Bangladesh