
TM Islamic Helper Security & Risk Analysis
wordpress.org/plugins/tm-islamic-helperIslamic Helper plugin for muslims prayer times. Don't delete this plugin.
Is TM Islamic Helper Safe to Use in 2026?
Use With Caution
Score 64/100TM Islamic Helper has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "tm-islamic-helper" plugin exhibits a concerning security posture due to a large number of unprotected AJAX handlers, representing a significant attack surface that could be exploited by unauthenticated users. While the plugin demonstrates good practices in its handling of SQL queries, utilizing prepared statements, the low percentage of properly escaped output is a major red flag. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially considering the plugin's history of a medium-severity XSS vulnerability. The presence of unsanitized paths in the taint analysis further exacerbates these concerns, suggesting potential for path traversal or file inclusion vulnerabilities, although no critical or high-severity taint flows were identified. The plugin's history of a recent medium-severity vulnerability, specifically XSS, coupled with the lack of robust output escaping, points to a pattern of insufficient input sanitization and output encoding, which attackers could leverage. While the plugin has a limited number of entry points and no direct file operations, the primary weaknesses lie in the lack of authentication on AJAX handlers and the inadequate output escaping, creating a considerable risk profile.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- Unsanitized paths in taint analysis
- Unpatched medium severity CVE
- Low number of nonce checks
- Low number of capability checks
TM Islamic Helper Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
TM Islamic Helper <= 1.0.1 - Reflected Cross-Site Scripting
TM Islamic Helper Code Analysis
Output Escaping
Data Flow Analysis
TM Islamic Helper Attack Surface
AJAX Handlers 14
Shortcodes 2
WordPress Hooks 12
Maintenance & Trust
TM Islamic Helper Maintenance & Trust
Maintenance Signals
Community Trust
TM Islamic Helper Alternatives
Salat Times
salat-times
Salat (Namaz) timetable for any location around the world!
Muslim Prayer Time-Salah/Iqamah
masjidal
Display the prayer(Athan) and/or Iqamah time for you masjid or location. Use as a widget or use the short codes and format it as you like.
Muslim Prayer Time BD – Prayer Reminder for Bangladesh
muslim-prayer-time-bd
A WordPress plugin to display proper prayer times specifically for Bangladeshi Muslims, including prayer reminders, widgets and customizable settings.
Prayer Times Bangla
prayer-times-bangla
A simple plugin to display daily Islamic prayer times in Bangla or English with location detection.
Daily Prayer Time
daily-prayer-time-for-mosques
Display prayer time in any screen, in any language and many more.
TM Islamic Helper Developer Profile
2 plugins · 110 total installs
How We Detect TM Islamic Helper
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tm-islamic-helper/dashboard/css/style.css/wp-content/plugins/tm-islamic-helper/dashboard/js/ui-choose.js/wp-content/plugins/tm-islamic-helper/dashboard/js/xlsx.full.min.js/wp-content/plugins/tm-islamic-helper/dashboard/js/ui-choose.js/wp-content/plugins/tm-islamic-helper/dashboard/js/xlsx.full.min.jstm-islamic-helper/dashboard/css/style.css?ver=tm-islamic-helper/dashboard/js/ui-choose.js?ver=tm-islamic-helper/dashboard/js/xlsx.full.min.js?ver=HTML / DOM Fingerprints
tmpray_dashboard_css