Salah World – Prayer and iQamah Timings for Masjids Security & Risk Analysis

wordpress.org/plugins/salah-world-prayer-iqamah-timings-for-your-masjids

Displays daily and monthly prayer and iqamah timings for your Masjid. Notify user when iqamah timings will change!

10 active installs v1.0 PHP + WP 3.5+ Updated Unknown
islammosque-timetablemuslimprayer-timesalah-time
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Salah World – Prayer and iQamah Timings for Masjids Safe to Use in 2026?

Generally Safe

Score 100/100

Salah World – Prayer and iQamah Timings for Masjids has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin "salah-world-prayer-iqamah-timings-for-your-masjids" version 1.0 presents a mixed security posture. While it has a clean vulnerability history with no recorded CVEs, indicating a potential focus on security by the developers, the static analysis reveals several concerning aspects. A significant portion of its attack surface, specifically 3 out of 6 entry points, lacks authentication checks, posing a risk of unauthorized access and potential exploitation. The presence of unsanitized taint flows, even if not categorized as critical or high in severity, suggests that data might be processed without proper validation, which could lead to vulnerabilities. Additionally, the low percentage of properly escaped output (21%) is a major concern, increasing the risk of Cross-Site Scripting (XSS) attacks.

While the plugin does not appear to have readily exploitable critical or high-severity vulnerabilities based on the provided data, the identified weaknesses are notable. The lack of capability checks on AJAX handlers is particularly worrying, as it means any authenticated user, regardless of their role, could potentially trigger these actions. The use of `unserialize` is also a potential danger if the input is not strictly controlled. The clean vulnerability history is a positive sign, but it does not negate the risks identified in the static and taint analysis. Moving forward, addressing the unprotected AJAX handlers, improving output escaping, and carefully sanitizing any data used with `unserialize` would significantly enhance the plugin's security.

Key Concerns

  • AJAX handlers without authentication checks
  • Taint flows with unsanitized paths (High severity)
  • Low percentage of properly escaped output
  • Use of dangerous function: unserialize
  • AJAX handlers without capability checks
Vulnerabilities
None known

Salah World – Prayer and iQamah Timings for Masjids Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Salah World – Prayer and iQamah Timings for Masjids Code Analysis

Dangerous Functions
1
Raw SQL Queries
4
6 prepared
Unescaped Output
93
25 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

unserialize$fontArray = unserialize( $fontsSeraliazed );dw-promobar-option.php:240

SQL Query Safety

60% prepared10 total queries

Output Escaping

21% escaped118 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
delete_row (fnbar_options.php:81)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Salah World – Prayer and iQamah Timings for Masjids Attack Surface

Entry Points6
Unprotected3

AJAX Handlers 4

authwp_ajax_dwpb-reset-cookiedw-promobar-option.php:389
authwp_ajax_delete_rowfnbar_options.php:11
authwp_ajax_new_rowfnbar_options.php:14
authwp_ajax_update_rowfnbar_options.php:17

Shortcodes 2

[dailySalah] functions.php:455
[monthlySalah] functions.php:456
WordPress Hooks 14
actionadmin_menudw-promobar-option.php:4
actionadmin_initdw-promobar-option.php:10
filterbody_classdw-promobar.php:69
actionwp_footerdw-promobar.php:308
actiondwpb_previvewdw-promobar.php:310
actionwp_footerdw-promobar.php:375
actionadmin_enqueue_scriptsdw-promobar.php:430
actionadmin_menufnbar_options.php:19
actionadmin_initfnbar_options.php:20
actionadmin_enqueue_scriptsfnbar_options.php:22
filterwidget_textfnbar_options.php:24
actionadmin_noticessalah-world.php:56
actionadmin_noticessalah-world.php:70
actioninitsalah-world.php:76
Maintenance & Trust

Salah World – Prayer and iQamah Timings for Masjids Maintenance & Trust

Maintenance Signals

WordPress version tested4.3.34
Last updatedUnknown
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

Salah World – Prayer and iQamah Timings for Masjids Developer Profile

lolislol

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Salah World – Prayer and iQamah Timings for Masjids

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/salah-world-prayer-iqamah-timings-for-your-masjids/dw-promobar.css/wp-content/plugins/salah-world-prayer-iqamah-timings-for-your-masjids/dw-promobar.js
Script Paths
/wp-content/plugins/salah-world-prayer-iqamah-timings-for-your-masjids/dw-promobar.js
Version Parameters
/wp-content/plugins/salah-world-prayer-iqamah-timings-for-your-masjids/dw-promobar.css?ver=/wp-content/plugins/salah-world-prayer-iqamah-timings-for-your-masjids/dw-promobar.js?ver=

HTML / DOM Fingerprints

CSS Classes
dwpb-push-pagedwpb-cover-pagedwpb-allow-closedwpb-show-bottomdwpb-twenty-fourteendwpb-ramain-topdwpb_responsive_extra_smalldwpb_responsive_small+2 more
HTML Comments
<!-- Exit if accessed directly -->
Data Attributes
dwpb_push_pagedwpb_ramain_topdwpb_show_bottomdwpb_closedwpb_responsive_extra_smalldwpb_responsive_small+24 more
JS Globals
DWPB_FOLDERDWPB_PATHdwpb_get_optiondwpb_body_classdwpb
FAQ

Frequently Asked Questions about Salah World – Prayer and iQamah Timings for Masjids