Shabbat Blocker Security & Risk Analysis

wordpress.org/plugins/shabbat-blocker

Blocks access to the site on Shabbat and Jewish holidays according to the selected city. Displays local candle lighting and havdalah times.

0 active installs v1.8.0 PHP 7.4+ WP 5.0+ Updated Dec 2, 2025
blockhebcalholidayscheduleshabbat
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shabbat Blocker Safe to Use in 2026?

Generally Safe

Score 100/100

Shabbat Blocker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The shabbat-blocker plugin v1.8.0 exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the attack surface. Furthermore, the code demonstrates good security practices with 100% of SQL queries utilizing prepared statements and a high percentage of output escaping (87%). The presence of nonce and capability checks indicates an awareness of common WordPress security vulnerabilities.

The taint analysis shows no critical or high severity flows, and the plugin has no recorded vulnerability history, which is highly encouraging. The bundled Freemius library, if kept up-to-date, is generally a stable component. The file operations and external HTTP requests are minimal and do not present immediate concerns without further context.

While the overall security is commendable, the 13% of improperly escaped output, though not flagged as critical in the taint analysis, represents a potential weakness for cross-site scripting (XSS) vulnerabilities, especially if user-controlled data is involved. The presence of two file operations and one external HTTP request warrants review to ensure they are handled securely and do not introduce vulnerabilities, although they are not flagged as problematic in the provided data. In conclusion, this plugin appears to be well-secured, with the primary area for potential improvement being the complete elimination of unescaped output.

Key Concerns

  • Improperly escaped output detected
Vulnerabilities
None known

Shabbat Blocker Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Shabbat Blocker Release Timeline

v1.8.0Current
v1.7.3
v1.7.2
v1.7.1
v1.7
Code Analysis
Analyzed Apr 16, 2026

Shabbat Blocker Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
10
66 escaped
Nonce Checks
1
Capability Checks
1
File Operations
2
External Requests
1
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

87% escaped76 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
shabbat_blocker_settings_page (shabbat-blocker.php:483)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Shabbat Blocker Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actiontemplate_redirectshabbat-blocker.php:322
actionadmin_menushabbat-blocker.php:472
actionwp_footershabbat-blocker.php:684
actionadmin_headshabbat-blocker.php:723
filtergettextshabbat-blocker.php:746
Maintenance & Trust

Shabbat Blocker Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 2, 2025
PHP min version7.4
Downloads330

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Shabbat Blocker Developer Profile

autopeak

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shabbat Blocker

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shabbat-blocker/shabbat-blocker-template.html
Version Parameters
shabbat-blocker/shabbat-blocker-template.html?ver=shabbat-blocker/shabbat-blocker-template.css?ver=shabbat-blocker/shabbat-blocker-template.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- Shabbat Blocker plugin --><!-- Powered by AUTOPEAK --><!-- Shabbat Blocker: Begin Template --><!-- Shabbat Blocker: End Template -->+21 more
Data Attributes
data-geonameiddata-tziddata-shabbat-start-localdata-shabbat-end-localdata-shabbat-end-utcdata-current-time-utc
JS Globals
ShabbatBlockerConfig
FAQ

Frequently Asked Questions about Shabbat Blocker