WP Hebrew Date Security & Risk Analysis

wordpress.org/plugins/wordpress-hebrew-date

Convert dates in wordpress to Hebrew dates.

700 active installs v2.0.5 PHP + WP 2.0+ Updated Sep 15, 2025
datehebrewjewish
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Hebrew Date Safe to Use in 2026?

Generally Safe

Score 100/100

WP Hebrew Date has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The wordpress-hebrew-date plugin v2.0.5 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities due to prepared statements, file operations, and external HTTP requests is commendable. Furthermore, the lack of known CVEs and a clean vulnerability history suggests diligent maintenance and secure development practices.

However, there are notable areas for improvement. A significant concern is the low percentage (13%) of properly escaped output, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities. Additionally, the plugin's reliance on a single shortcode as an entry point, while currently unprotected, is a weakness that could be exploited if not properly secured. The absence of nonce checks and capability checks on this shortcode presents an unaddressed risk.

In conclusion, while the plugin benefits from a lack of known serious vulnerabilities and robust practices in areas like SQL handling, the output escaping and lack of protective measures on its shortcode entry point are significant weaknesses that warrant attention. The overall security is fair, but not excellent.

Key Concerns

  • Low percentage of properly escaped output
  • Shortcode lacks nonce checks
  • Shortcode lacks capability checks
Vulnerabilities
None known

WP Hebrew Date Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WP Hebrew Date Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

13% escaped16 total outputs
Attack Surface

WP Hebrew Date Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[today_hebdate] heb_date.php:21
WordPress Hooks 8
actionadmin_noticesheb_date.php:17
actionadmin_menuheb_date.php:22
actionwidgets_initheb_date.php:23
filterget_comment_dateheb_date.php:27
filterthe_dateheb_date.php:28
filterget_the_timeheb_date.php:29
filterget_the_dateheb_date.php:30
actionadmin_initheb_date.php:308
Maintenance & Trust

WP Hebrew Date Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 15, 2025
PHP min version
Downloads15K

Community Trust

Rating100/100
Number of ratings9
Active installs700
Developer Profile

WP Hebrew Date Developer Profile

hatul

4 plugins · 1K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect WP Hebrew Date

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wordpress-hebrew-date/hebdate.css/wp-content/plugins/wordpress-hebrew-date/js/hebdate.js
Script Paths
/wp-content/plugins/wordpress-hebrew-date/js/hebdate.js

HTML / DOM Fingerprints

CSS Classes
hebdate_hide_alafimhebdate_lang
Data Attributes
onfocus="hebdate_format_custom_radio.checked=true"
JS Globals
hebdate_format_custom_radio
Shortcode Output
[today_hebdate]
FAQ

Frequently Asked Questions about WP Hebrew Date