
Simple Hijri Calendar Security & Risk Analysis
wordpress.org/plugins/simple-hijri-calendarVery simple hijri calendar widget plugin.
Is Simple Hijri Calendar Safe to Use in 2026?
Generally Safe
Score 85/100Simple Hijri Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'simple-hijri-calendar' plugin v2.1.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any identifiable attack surface points, dangerous functions, file operations, external HTTP requests, or raw SQL queries is highly commendable. Furthermore, the plugin demonstrates good practices by exclusively using prepared statements for its SQL operations.
However, a significant concern arises from the output escaping. With 61 total outputs and only 43% properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of any identified nonce or capability checks, while potentially mitigated by the minimal attack surface, still presents a weakness if any entry points were to be discovered or introduced in future versions. The clean vulnerability history is a positive indicator, suggesting a history of secure development, but it does not negate the risks identified in the current code analysis.
In conclusion, while the plugin's foundational security regarding external interactions and data manipulation appears robust, the insufficient output escaping poses a notable risk. Developers should prioritize addressing the XSS vulnerabilities, and consider implementing capability checks to further harden the plugin against potential future threats.
Key Concerns
- Insufficient output escaping (43% proper)
- No nonce checks implemented
- No capability checks implemented
Simple Hijri Calendar Security Vulnerabilities
Simple Hijri Calendar Code Analysis
Output Escaping
Simple Hijri Calendar Attack Surface
WordPress Hooks 5
Maintenance & Trust
Simple Hijri Calendar Maintenance & Trust
Maintenance Signals
Community Trust
Simple Hijri Calendar Alternatives
Hijri Calendar
hijri-calendar
Easily display current Hijri/Islamic date (according to hijri calendar), anywhere in your wordpress blog!
Xllentech English Islamic Calendar
xllentech-english-islamic-calendar
The Best English Islamic Calendar plugin on WordPress.
Hijri
hijri
Display Hijri and/or Gregorian dates on your blog.
Hijri Calendar Widget
hijri-calendar-widget
Wordpress plugin for historically accurate Hijri conversions.
ICOUK Hijri Date
icouk-hijri-date
Display the current Hijri date on your WordPress website using the Moon Sighting UK API.
Simple Hijri Calendar Developer Profile
2 plugins · 100 total installs
How We Detect Simple Hijri Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-hijri-calendar/assets/css/style.css/wp-content/plugins/simple-hijri-calendar/assets/js/scripts.js/wp-content/plugins/simple-hijri-calendar/assets/js/scripts.jssimple-hijri-calendar/assets/css/style.css?ver=simple-hijri-calendar/assets/js/scripts.js?ver=HTML / DOM Fingerprints
hijri-calendarhijriEOF