Salat Times Security & Risk Analysis

wordpress.org/plugins/salat-times

Salat (Namaz) timetable for any location around the world!

600 active installs v3.7 PHP 5.6+ WP 3.0+ Updated Feb 27, 2026
islammuslimnamazprayersalat
100
A · Safe
CVEs total1
Unpatched0
Last CVENov 2, 2022
Safety Verdict

Is Salat Times Safe to Use in 2026?

Generally Safe

Score 100/100

Salat Times has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 2, 2022Updated 1mo ago
Risk Assessment

The salat-times v3.7 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, using prepared statements exclusively for SQL queries, and having no external HTTP requests. The limited attack surface, consisting solely of one shortcode with no apparent direct unprotected entry points, is also a strength. However, several concerns warrant attention. The taint analysis revealed flows with unsanitized paths, indicating a potential for vulnerabilities if these paths are exposed to user input, despite the absence of critical or high severity findings in this analysis. Furthermore, a significant portion of output (25%) is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities. The plugin's history shows one medium-severity CVE related to XSS, which was patched, suggesting the developers address security issues. However, the presence of past XSS vulnerabilities coupled with unescaped output in the current version is a recurring concern.

Key Concerns

  • Taint flows with unsanitized paths
  • Unescaped output detected (25%)
  • No capability checks
  • No nonce checks
  • Previous medium XSS vulnerability
Vulnerabilities
1

Salat Times Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2022-2983medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Salat Times < = 3.2.1 - Authenticated (Administrator+) Stored Cross-Site Scripting

Nov 2, 2022 Patched in 3.2.2 (447d)
Code Analysis
Analyzed Mar 16, 2026

Salat Times Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
54 escaped
Nonce Checks
0
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped72 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
salat_times_options_page (salat_times_admin.php:5)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Salat Times Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[daily_salat_times] salat-times.php:371
WordPress Hooks 4
actionwp_enqueue_scriptssalat-times.php:366
actionadmin_enqueue_scriptssalat-times.php:367
actionadmin_menusalat_times_admin.php:792
actionadmin_initsalat_times_admin.php:793
Maintenance & Trust

Salat Times Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 27, 2026
PHP min version5.6
Downloads27K

Community Trust

Rating96/100
Number of ratings9
Active installs600
Developer Profile

Salat Times Developer Profile

ALI IMRAN

5 plugins · 7K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
447 days
View full developer profile
Detection Fingerprints

How We Detect Salat Times

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/salat-times/style.css/wp-content/plugins/salat-times/js/salat-times.js
Script Paths
/wp-content/plugins/salat-times/js/salat-times.js
Version Parameters
salat-times/style.css?ver=salat-times/js/salat-times.js?ver=

HTML / DOM Fingerprints

CSS Classes
st_tablest_widget
Data Attributes
data-st_options
JS Globals
salat_times_data
Shortcode Output
<!-- salat times widget --><table class="st_widget"
FAQ

Frequently Asked Questions about Salat Times