
Shamor Security & Risk Analysis
wordpress.org/plugins/shamorRedirect user out of your site on Shabbat and Holiday.
Is Shamor Safe to Use in 2026?
Generally Safe
Score 100/100Shamor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "shamor" plugin version 1.8.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, utilizing prepared statements exclusively, and has no recorded vulnerabilities (CVEs) or active security advisories. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its current stable state. However, significant concerns arise from the attack surface analysis. Two AJAX handlers are present, and alarmingly, both lack authentication checks. This creates a direct pathway for unauthenticated users to interact with potentially sensitive plugin functionalities, posing a notable risk. The taint analysis also shows no flows analyzed, which, while not indicating a problem, means this aspect of security hasn't been thoroughly vetted.
Despite the lack of a known vulnerability history, the presence of unprotected AJAX endpoints is a critical weakness that could be exploited. The plugin's strengths lie in its SQL handling and lack of known past issues, but the immediate risk of unauthenticated access to AJAX endpoints cannot be overlooked. A balanced conclusion suggests that while the plugin has avoided historical vulnerabilities and employs good database practices, its current implementation introduces a significant and immediate security concern due to the exposed AJAX handlers. Further security auditing, particularly around taint analysis and output escaping, would be beneficial.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
Shamor Security Vulnerabilities
Shamor Code Analysis
Output Escaping
Shamor Attack Surface
AJAX Handlers 2
Shortcodes 2
WordPress Hooks 8
Maintenance & Trust
Shamor Maintenance & Trust
Maintenance Signals
Community Trust
Shamor Alternatives
Holy Day Off
holy-day-off
The #1 Shabbat & Jewish holiday plugin for WordPress. Automatically close your WooCommerce store on schedule. Set your city once, rest every week.
WP-Shabbat
wp-shabbat
Close site or display popup message on Shabbat and Holidays by identifying the address of the user IP and close to 40 km
WP Hebrew Date
wordpress-hebrew-date
Convert dates in wordpress to Hebrew dates.
CalJ
calj
Display the Shabbat times (zmanim) for the city of your choice.
Shabbat Zman Widget
adatosystems-friday-zmanim
THIS PLUGIN IS NO LONGER SUPPORTED!!
Shamor Developer Profile
1 plugin · 400 total installs
How We Detect Shamor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/shamor/block_template.phpHTML / DOM Fingerprints
<div class="wp-shammor-countdown-container"></div><div class="wp-shamor-havdalah-hour-container"></div>