
Muslim Prayer Times Security & Risk Analysis
wordpress.org/plugins/muslim-prayer-timesAdd accurate prayer times and iqama schedules to your WordPress site using blocks or shortcodes.
Is Muslim Prayer Times Safe to Use in 2026?
Generally Safe
Score 100/100Muslim Prayer Times has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "muslim-prayer-times" plugin v1.2.1 exhibits a generally good security posture, with strong adherence to secure coding practices. The vast majority of SQL queries utilize prepared statements, and nearly all output is properly escaped, significantly mitigating common web vulnerabilities. The plugin also demonstrates a commendable lack of known historical vulnerabilities, suggesting a history of responsible development and maintenance. The presence of nonce checks and capability checks on most entry points further strengthens its defenses.
However, the analysis does reveal a few areas of concern. The presence of 3 REST API routes without permission callbacks represents a direct attack vector that could be exploited if sensitive data or functionality is exposed. Additionally, the taint analysis identified 2 flows with unsanitized paths, which, although not classified as critical or high severity, warrant careful investigation as they could potentially lead to path traversal or other file-related vulnerabilities. While the overall attack surface is protected, these unprotected entry points are the most significant immediate risk.
In conclusion, "muslim-prayer-times" v1.2.1 is a relatively secure plugin with excellent output escaping and SQL handling. The lack of historical vulnerabilities is a very positive sign. The primary areas for improvement and concern lie in securing the identified unprotected REST API routes and thoroughly reviewing the identified unsanitized path flows to ensure no exploitable vulnerabilities exist. Addressing these points would further enhance the plugin's security.
Key Concerns
- REST API routes without permission callbacks
- Flows with unsanitized paths
Muslim Prayer Times Security Vulnerabilities
Muslim Prayer Times Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Muslim Prayer Times Attack Surface
AJAX Handlers 12
REST API Routes 3
Shortcodes 3
WordPress Hooks 16
Maintenance & Trust
Muslim Prayer Times Maintenance & Trust
Maintenance Signals
Community Trust
Muslim Prayer Times Alternatives
Muslim Prayer Time-Salah/Iqamah
masjidal
Display the prayer(Athan) and/or Iqamah time for you masjid or location. Use as a widget or use the short codes and format it as you like.
Salah World – Prayer and iQamah Timings for Masjids
salah-world-prayer-iqamah-timings-for-your-masjids
Displays daily and monthly prayer and iqamah timings for your Masjid. Notify user when iqamah timings will change!
Zakah Calculator
zakah-calculator
It is a simple and easy way to know how to fulfill the obligation of Zakah.
Hijri Calendar
hijri-calendar
Easily display current Hijri/Islamic date (according to hijri calendar), anywhere in your wordpress blog!
Beautiful Salat
beautiful-salat
Simple, beautiful, lightweight prayer times plugin with Gutenberg blocks for easy editing.
Muslim Prayer Times Developer Profile
2 plugins · 100 total installs
How We Detect Muslim Prayer Times
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/muslim-prayer-times/assets/css/style.css/wp-content/plugins/muslim-prayer-times/blocks/daily-prayer-times/block.js/wp-content/plugins/muslim-prayer-times/blocks/daily-prayer-times/carousel.js/wp-content/plugins/muslim-prayer-times/blocks/daily-prayer-times/style.css/wp-content/plugins/muslim-prayer-times/blocks/monthly-prayer-times/block.js/wp-content/plugins/muslim-prayer-times/blocks/monthly-prayer-times/style.css/wp-content/plugins/muslim-prayer-times/blocks/live-prayer-times/block.js/wp-content/plugins/muslim-prayer-times/blocks/live-prayer-times/style.css+2 moreplugins_url('block.js', __FILE__)plugins_url('carousel.js', __FILE__)plugins_url('block.js', __FILE__)plugins_url('carousel.js', __FILE__)plugins_url('block.js', __FILE__)plugins_url('carousel.js', __FILE__)+6 morefilemtime(plugin_dir_path(__FILE__) . 'block.js')filemtime(plugin_dir_path(__FILE__) . 'carousel.js')filemtime(plugin_dir_path(__FILE__) . 'style.css')1.0.0filemtime(plugin_dir_path(__FILE__) . 'block.js')filemtime(plugin_dir_path(__FILE__) . 'style.css')filemtime(plugin_dir_path(__FILE__) . 'block.js')filemtime(plugin_dir_path(__FILE__) . 'style.css')filemtime(plugin_dir_path(__FILE__) . 'block.js')filemtime(plugin_dir_path(__FILE__) . 'style.css')HTML / DOM Fingerprints
wp-block-prayer-times-daily-prayer-timesprayer-times-tableprayer-times-table__headerprayer-times-table__rowprayer-times-table__cellprayer-times-table__hijriprayer-times-table__fajrprayer-times-table__dhuhr+10 more/**
* Daily Muslim Prayer Times Gutenberg Block
*//**
* Register the block
*//**
* Render the Daily Muslim Prayer Times block on the frontend
*/<!-- Settings Page -->+5 moredata-show-datedata-show-hijri-datedata-show-sunrisedata-table-styledata-font-sizedata-show-arrows+4 morewindow.muslprti_prayer_times_carouselwindow.muslprti_live_prayer_times/wp-json/muslim-prayer-times/v1/prayer-times/wp-json/muslim-prayer-times/v1/settings[prayer_times][prayer_times_daily][prayer_times_monthly][prayer_times_live]