
NGS JS Salat Times Security & Risk Analysis
wordpress.org/plugins/ngs-js-salat-timesProvide Islamic Prayer Times computed on client side.
Is NGS JS Salat Times Safe to Use in 2026?
Generally Safe
Score 85/100NGS JS Salat Times has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The ngs-js-salat-times plugin version 1.3 exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs), no external HTTP requests, and its SQL queries are 100% prepared, indicating good practices in these areas. The attack surface, while containing two shortcodes, has no directly identified unprotected entry points.
However, significant concerns arise from the static code analysis. The most glaring issue is the complete lack of output escaping (0% properly escaped). This is a critical vulnerability that could lead to cross-site scripting (XSS) attacks if user-supplied data is ever rendered by the plugin without proper sanitization. Additionally, the absence of nonce checks and capability checks, especially given the presence of shortcodes which are often interaction points, leaves the plugin vulnerable to unauthorized actions or privilege escalation. The file operations also warrant attention, as their implementation without context could introduce risks.
Given the absence of historical vulnerabilities, it's difficult to draw conclusions about long-term maintenance. However, the current codebase shows critical flaws in output handling and authorization mechanisms that far outweigh the positive aspects. The plugin's current state suggests a high risk of XSS and potential unauthorized operations.
Key Concerns
- 0% of outputs are properly escaped
- 0 nonces checked
- 0 capability checks
- File operations present without context
NGS JS Salat Times Security Vulnerabilities
NGS JS Salat Times Code Analysis
Output Escaping
NGS JS Salat Times Attack Surface
Shortcodes 2
WordPress Hooks 5
Maintenance & Trust
NGS JS Salat Times Maintenance & Trust
Maintenance Signals
Community Trust
NGS JS Salat Times Alternatives
No alternatives data available yet.
NGS JS Salat Times Developer Profile
1 plugin · 10 total installs
How We Detect NGS JS Salat Times
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ngs-js-salat-times/templates/default_monthly.tmpl/wp-content/plugins/ngs-js-salat-times/templates/default_daily.tmplHTML / DOM Fingerprints
ngsjsst-salatsngsjsst-oddngsjsst-todayngsjsst-dayngsjsst-timewgt_title1wgt_title2latitudelongitudelocationlocale+22 more<div class="ngs-js-salat-time-anchor"<div class="ngs-js-salat-time-anchor" daily="true"