
Weekly Shabbat Times Security & Risk Analysis
wordpress.org/plugins/weekly-shabbat-timesThis plugin creates shortcode to display the Shabbat portion titles, candle lighting times, Havdalah times, etc. of the current week.
Is Weekly Shabbat Times Safe to Use in 2026?
Generally Safe
Score 85/100Weekly Shabbat Times has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "weekly-shabbat-times" plugin version 1.1.0 exhibits a generally good security posture based on the provided static analysis. It has a minimal attack surface with only one entry point (a shortcode), and importantly, no unprotected entry points were identified. The code demonstrates strong security practices with 100% of SQL queries utilizing prepared statements and 100% of output being properly escaped. There were no identified dangerous functions, external HTTP requests, or critical/high severity taint flows, which are all positive indicators.
However, there are a few areas that warrant attention. The plugin has a single file operation, and while no specific risks are highlighted, any file operation carries inherent risk if not handled with extreme care, especially regarding user-supplied input. More significantly, the absence of nonce checks and capability checks is a notable concern. While the analysis indicates no unprotected AJAX or REST API routes, this doesn't preclude potential vulnerabilities if the shortcode's functionality could be manipulated by unauthenticated users without proper verification. The lack of historical vulnerabilities is a strength, suggesting the developers have a good track record, but it doesn't negate the need for robust security measures within the current version.
In conclusion, "weekly-shabbat-times" v1.1.0 is relatively secure due to its limited attack surface and strong data handling practices. The main weaknesses lie in the potential for insufficient authorization checks for its shortcode, a common area for exploitation if not implemented carefully. The file operation also presents a potential, albeit unquantified, risk. Addressing the missing nonce and capability checks would significantly strengthen its security.
Key Concerns
- Missing nonce checks
- Missing capability checks
- File operation present (potential risk)
Weekly Shabbat Times Security Vulnerabilities
Weekly Shabbat Times Code Analysis
Weekly Shabbat Times Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Weekly Shabbat Times Maintenance & Trust
Maintenance Signals
Community Trust
Weekly Shabbat Times Alternatives
Shamor
shamor
Redirect user out of your site on Shabbat and Holiday.
Shabbat Zman Widget
adatosystems-friday-zmanim
THIS PLUGIN IS NO LONGER SUPPORTED!!
Holy Day Off
holy-day-off
The #1 Shabbat & Jewish holiday plugin for WordPress. Automatically close your WooCommerce store on schedule. Set your city once, rest every week.
WP-Shabbat
wp-shabbat
Close site or display popup message on Shabbat and Holidays by identifying the address of the user IP and close to 40 km
Keep Sabbath
keep-sabbath
Plugin to help you observe the Biblical Sabbath & Holy days by automatically redirecting specific pages of your site on those days.
Weekly Shabbat Times Developer Profile
4 plugins · 10K total installs
How We Detect Weekly Shabbat Times
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/weekly-shabbat-times/weekly-shabbat-times.phpHTML / DOM Fingerprints
[hebcal_sc][hebcal_sc category="parashat"][hebcal_sc param="title"][hebcal_sc param="title" category="parashat"]