
Prayer Time & Calender Security & Risk Analysis
wordpress.org/plugins/prayer-time-calenderWordPress Plugin for show prayer time including custom search, auto location (geoIP), islamic calender. In both shortcode and widget supports.
Is Prayer Time & Calender Safe to Use in 2026?
Generally Safe
Score 85/100Prayer Time & Calender has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The prayer-time-calender plugin v1.2 presents a mixed security posture. On the positive side, there are no recorded historical vulnerabilities and the plugin utilizes prepared statements for all SQL queries. However, significant concerns arise from the static analysis, particularly regarding input validation and authentication. The presence of two unprotected AJAX handlers significantly increases the attack surface, offering potential entry points for attackers to exploit without proper authorization. Furthermore, the complete lack of output escaping across all identified outputs is a critical weakness, leaving the plugin highly susceptible to cross-site scripting (XSS) attacks. The absence of nonce checks on AJAX endpoints exacerbates this risk.
While the plugin's vulnerability history is clean, this should not be interpreted as a guarantee of current security. The identified weaknesses in the code itself, specifically the unprotected entry points and pervasive unescaped output, represent immediate and serious risks that could be leveraged by an attacker. The absence of taint analysis results doesn't inherently mean there are no vulnerabilities, but rather that the analysis either couldn't be performed or didn't find any specific flows. The overall conclusion is that despite the lack of historical exploits and good SQL practices, the current version of prayer-time-calender is highly vulnerable due to critical deficiencies in handling user input and securing its entry points.
Key Concerns
- Unprotected AJAX handlers
- No output escaping
- No nonce checks on AJAX
- No capability checks
Prayer Time & Calender Security Vulnerabilities
Prayer Time & Calender Code Analysis
Output Escaping
Prayer Time & Calender Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Prayer Time & Calender Maintenance & Trust
Maintenance Signals
Community Trust
Prayer Time & Calender Alternatives
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
contact-form-plugin
The most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
Apollo13 Framework Extensions
apollo13-framework-extensions
Adds custom post types, shortcodes and some features that are used in themes built on Apollo13 Framework.
Kaya QR Code Generator
kaya-qr-code-generator
Generate QR Code through Widgets and Shortcodes, without any dependencies.
Donations via PayPal
paypal-donations
Easy, simple setup to add a PayPal Donation button as a Widget or with a shortcode.
Reusable Blocks Extended
reusable-blocks-extended
Extend Gutenberg Reusable Blocks feature with a complete admin panel, widgets, shortcodes and PHP functions.
Prayer Time & Calender Developer Profile
3 plugins · 30 total installs
How We Detect Prayer Time & Calender
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/prayer-time-calender/style.css/wp-content/plugins/prayer-time-calender/ajax_form_submit.js/wp-content/plugins/prayer-time-calender/functions.js/wp-content/plugins/prayer-time-calender/ajax_form_submit.js/wp-content/plugins/prayer-time-calender/functions.jsprayer-time-calender/style.css?ver=prayer-time-calender/ajax_form_submit.js?ver=prayer-time-calender/functions.js?ver=HTML / DOM Fingerprints
[ma_prayer_viewer]