Weekly Shabbat Times Security & Risk Analysis

wordpress.org/plugins/weekly-shabbat-times

This plugin creates shortcode to display the Shabbat portion titles, candle lighting times, Havdalah times, etc. of the current week.

20 active installs v1.1.0 PHP + WP 4.7+ Updated Feb 26, 2021
shabbat
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Weekly Shabbat Times Safe to Use in 2026?

Generally Safe

Score 85/100

Weekly Shabbat Times has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "weekly-shabbat-times" plugin version 1.1.0 exhibits a generally good security posture based on the provided static analysis. It has a minimal attack surface with only one entry point (a shortcode), and importantly, no unprotected entry points were identified. The code demonstrates strong security practices with 100% of SQL queries utilizing prepared statements and 100% of output being properly escaped. There were no identified dangerous functions, external HTTP requests, or critical/high severity taint flows, which are all positive indicators.

However, there are a few areas that warrant attention. The plugin has a single file operation, and while no specific risks are highlighted, any file operation carries inherent risk if not handled with extreme care, especially regarding user-supplied input. More significantly, the absence of nonce checks and capability checks is a notable concern. While the analysis indicates no unprotected AJAX or REST API routes, this doesn't preclude potential vulnerabilities if the shortcode's functionality could be manipulated by unauthenticated users without proper verification. The lack of historical vulnerabilities is a strength, suggesting the developers have a good track record, but it doesn't negate the need for robust security measures within the current version.

In conclusion, "weekly-shabbat-times" v1.1.0 is relatively secure due to its limited attack surface and strong data handling practices. The main weaknesses lie in the potential for insufficient authorization checks for its shortcode, a common area for exploitation if not implemented carefully. The file operation also presents a potential, albeit unquantified, risk. Addressing the missing nonce and capability checks would significantly strengthen its security.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • File operation present (potential risk)
Vulnerabilities
None known

Weekly Shabbat Times Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Weekly Shabbat Times Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0
Attack Surface

Weekly Shabbat Times Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[hebcal_sc] hebcal-json.php:18
WordPress Hooks 1
filterthe_titlehebcal-json.php:21
Maintenance & Trust

Weekly Shabbat Times Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedFeb 26, 2021
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Weekly Shabbat Times Developer Profile

Aaron Reimann

4 plugins · 10K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Weekly Shabbat Times

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/weekly-shabbat-times/weekly-shabbat-times.php

HTML / DOM Fingerprints

Shortcode Output
[hebcal_sc][hebcal_sc category="parashat"][hebcal_sc param="title"][hebcal_sc param="title" category="parashat"]
FAQ

Frequently Asked Questions about Weekly Shabbat Times