
Offen Security & Risk Analysis
wordpress.org/plugins/offenEasily store and display the opening hours of your company. Including display of Open/Closed, Holidays etc.
Is Offen Safe to Use in 2026?
Generally Safe
Score 85/100Offen has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "offen" v3.9 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and having no recorded vulnerabilities in its history. This suggests a history of generally secure development.
However, the static analysis reveals notable areas of concern. The presence of an AJAX handler without authentication checks represents a significant attack vector. Additionally, the `unserialize` function, a known risk if used with untrusted input, is present. The relatively low percentage of properly escaped output (46%) also indicates a potential for cross-site scripting (XSS) vulnerabilities.
While the plugin has no known CVEs, the identified code signals warrant attention. The lack of taint analysis data limits the depth of assessment, but the static findings highlight specific areas where attackers could potentially exploit the plugin. The overall risk is moderate, leaning towards higher due to the unprotected AJAX endpoint and the `unserialize` function.
Key Concerns
- Unprotected AJAX handler
- Usage of unserialize function
- Low percentage of properly escaped output
Offen Security Vulnerabilities
Offen Code Analysis
Dangerous Functions Found
Output Escaping
Offen Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Offen Maintenance & Trust
Maintenance Signals
Community Trust
Offen Alternatives
No alternatives data available yet.
Offen Developer Profile
3 plugins · 620 total installs
How We Detect Offen
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/offen/templates/assets/vendor/navigation/css/style.css/wp-content/plugins/offen/templates/assets/vendor/timedropper/timedropper.min.css