
Penanggalan Hijriyah & Masehi Security & Risk Analysis
wordpress.org/plugins/penanggalan-hijriyah-masehiMemudahkan anda untuk menampilkan penanggalan Hijriyah & Masehi // Easy to add Hijri and Gregorian dates
Is Penanggalan Hijriyah & Masehi Safe to Use in 2026?
Generally Safe
Score 85/100Penanggalan Hijriyah & Masehi has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "penanggalan-hijriyah-masehi" plugin v2.0 exhibits a generally good security posture with no recorded vulnerabilities or CVEs. The static analysis reveals no dangerous functions, no SQL queries that are not prepared statements, and no file operations or external HTTP requests, all of which are positive security indicators. The limited attack surface, with only one shortcode and no unprotected entry points, further contributes to its perceived safety.
However, there are significant concerns regarding output escaping and taint analysis. A mere 6% of outputs are properly escaped, indicating a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, while not yielding critical or high severity issues, did find two flows with unsanitized paths, suggesting potential for data manipulation or unintended behavior if these paths are exploited, even if the immediate impact is not severe. The absence of nonce checks and capability checks, while not directly leading to a deduction based on the limited entry points, is a general weakness that could be exploited if the attack surface were to expand or if new entry points were introduced in future versions.
In conclusion, while the plugin benefits from a clean vulnerability history and a small, seemingly well-controlled attack surface, the severe lack of output escaping is a critical flaw that exposes users to XSS attacks. The unsanitized taint flows, though not currently critical, warrant attention. Developers should prioritize addressing the output escaping issues and carefully review the identified taint flows.
Key Concerns
- Low percentage of properly escaped output
- Taint flows with unsanitized paths
- Missing nonce checks
- Missing capability checks
Penanggalan Hijriyah & Masehi Security Vulnerabilities
Penanggalan Hijriyah & Masehi Code Analysis
Output Escaping
Data Flow Analysis
Penanggalan Hijriyah & Masehi Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Penanggalan Hijriyah & Masehi Maintenance & Trust
Maintenance Signals
Community Trust
Penanggalan Hijriyah & Masehi Alternatives
Simple Hijri Calendar
simple-hijri-calendar
Very simple hijri calendar widget plugin.
Hijri
hijri
Display Hijri and/or Gregorian dates on your blog.
LTR RTL Admin content
ltrrtl-admin-content
Enable LTR in admin content area. Click the admin bar button to switch between RTL & LTR.
Widget Visibility Time Scheduler
widget-visibility-time-scheduler
Control the visibility of each widget easily based on date, time and weekday.
Khattat – Arabic Fonts
khattat-arabic-fonts
Choose a beautiful Arabic font for your site from over 110 stunning fonts to enhance user experience.
Penanggalan Hijriyah & Masehi Developer Profile
2 plugins · 20 total installs
How We Detect Penanggalan Hijriyah & Masehi
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/penanggalan-hijriyah-masehi/style.css/wp-content/plugins/penanggalan-hijriyah-masehi/js/script.js/wp-content/plugins/penanggalan-hijriyah-masehi/js/script.jspenanggalan-hijriyah-masehi/style.css?ver=penanggalan-hijriyah-masehi/js/script.js?ver=HTML / DOM Fingerprints
hijriyahmasehiseparatorPHM_adjustPHM_separatorPHM_stylePHM_hijrdayPHM_hijrmonthPHM_masehiday+1 more