
WP-Persian Security & Risk Analysis
wordpress.org/plugins/wp-persianFast and Powerful plugin for Jalali calendar and Farsi language support in Wordpress and standard plugins.
Is WP-Persian Safe to Use in 2026?
Generally Safe
Score 85/100WP-Persian has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-persian plugin v3.3.0 presents a mixed security profile. On the positive side, the plugin exhibits a very small attack surface, with no identifiable AJAX handlers, REST API routes, shortcodes, or cron events exposed. Furthermore, there are no known vulnerabilities (CVEs) associated with this plugin, and its history is clean, suggesting a generally well-maintained codebase.
However, the static analysis reveals some areas of concern. A significant portion of the output (57%) is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. While only one capability check is present, the lack of any nonce checks on the zero AJAX handlers is notable, though the absence of any AJAX handlers itself mitigates this risk currently. The taint analysis indicated two flows with unsanitized paths, which, while not classified as critical or high, warrant attention as potential vectors for path traversal or information disclosure if these paths are ever exposed to external input.
In conclusion, the plugin's strength lies in its minimal attack surface and lack of known vulnerabilities. The primary weaknesses identified are the significant number of unescaped outputs and the presence of unsanitized paths in the taint analysis. These issues, while not currently leading to high-severity exploitable vulnerabilities based on the provided data, represent potential risks that should be addressed to improve the plugin's overall security posture.
Key Concerns
- High percentage of unescaped output
- Taint flows with unsanitized paths
- No nonce checks on AJAX handlers
WP-Persian Security Vulnerabilities
WP-Persian Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
WP-Persian Attack Surface
WordPress Hooks 60
Maintenance & Trust
WP-Persian Maintenance & Trust
Maintenance Signals
Community Trust
WP-Persian Alternatives
Persian Date
persian-date
تاریخ شمسی برای وردپرس
persian date shortcode
persian-date-short-code
Easy way for Display persian date in multi format and unlimited color in wordpress site
Persian Text and Date Converter
persian-text-and-date-converter
بهطور خودکار حروف عربی، اعداد و تاریخ میلادی را در محتوای وردپرس، نظرات، صفحات و آرشیوها به فارسی تبدیل میکند.
wp-jalali
wp-jalali
Full Jalali calendar support for Wordpress and localization improvements for Persian/Afghan/Tajik users.
Persian date for codestar framework
persian-date-for-codestar-framework
Codestar Framework Is A Simple and Lightweight WordPress Option Framework for Themes and Plugins. Persian date for codestar framework adds a new field …
WP-Persian Developer Profile
1 plugin · 9K total installs
How We Detect WP-Persian
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-persian/assets/css/wpp-context.css/wp-content/plugins/wp-persian/assets/js/wpp-context.js/wp-content/plugins/wp-persian/assets/css/wp-persian.css/wp-content/plugins/wp-persian/assets/js/wpp-jalali.js/wp-content/plugins/wp-persian/assets/js/wp-persian.js/wp-content/plugins/wc-persian/assets/js/wc-persian.js/wp-content/plugins/wc-persian/assets/css/wc-persian.css/wp-content/plugins/wp-persian/assets/js/wpp-context.js/wp-content/plugins/wp-persian/assets/js/wpp-jalali.js/wp-content/plugins/wp-persian/assets/js/wp-persian.js/wp-content/plugins/wc-persian/assets/js/wc-persian.jswp-persian/assets/css/wpp-context.css?ver=wp-persian/assets/js/wpp-context.js?ver=wp-persian/assets/css/wp-persian.css?ver=wp-persian/assets/js/wpp-jalali.js?ver=wp-persian/assets/js/wp-persian.js?ver=wc-persian/assets/js/wc-persian.js?ver=wc-persian/assets/css/wc-persian.css?ver=HTML / DOM Fingerprints
window.wp_persianwindow.WP_Persian