
GoPrayer Security & Risk Analysis
wordpress.org/plugins/wp-prayers-requestAn application that allows an organization share, update, and manage prayer requests.
Is GoPrayer Safe to Use in 2026?
Generally Safe
Score 99/100GoPrayer has a strong security track record. Known vulnerabilities have been patched promptly.
The "wp-prayers-request" plugin v2.4.9 exhibits a generally good security posture, adhering to several best practices. The static analysis reveals no dangerous functions, all SQL queries utilize prepared statements, and the vast majority of output is properly escaped. Importantly, there are no identified taint flows with unsanitized paths, indicating that data is likely handled safely within the code. The plugin also implements nonce checks on all identified entry points and has a relatively small attack surface without authentication. However, a significant concern arises from its vulnerability history. With two medium-severity CVEs, both of which were Cross-Site Request Forgery (CSRF) vulnerabilities, it suggests a pattern of insecure handling of user actions. While there are currently no unpatched vulnerabilities, this history points to potential weaknesses in enforcing proper authorization and validation for sensitive operations, which could be exploited if similar flaws are introduced in future updates. The lack of capability checks on AJAX handlers, despite nonce checks, is a potential area for improvement, as it relies solely on nonces for authorization which can sometimes be bypassed in certain scenarios.
Key Concerns
- Two medium severity CSRF vulnerabilities in history
- No capability checks on AJAX handlers
GoPrayer Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Prayer II <= 2.4.7 - Cross-Site Request Forgery to Settings Update
WP Prayer II <= 2.4.7 - Cross-Site Request Forgery to Email Settings Update
GoPrayer Code Analysis
Output Escaping
Data Flow Analysis
GoPrayer Attack Surface
AJAX Handlers 4
Shortcodes 2
WordPress Hooks 13
Maintenance & Trust
GoPrayer Maintenance & Trust
Maintenance Signals
Community Trust
GoPrayer Alternatives
GoPray
gopray
Prayer request application to allow users to submit requests or pray for existing requests
Church Content – Sermons, Events and More
church-theme-content
Provides an interface for managing sermons, events, people and locations. A compatible theme is required for presenting content from these church-cent …
Daily Prayer Time
daily-prayer-time-for-mosques
Display prayer time in any screen, in any language and many more.
Salat Times
salat-times
Salat (Namaz) timetable for any location around the world!
Muslim Prayer Time-Salah/Iqamah
masjidal
Display the prayer(Athan) and/or Iqamah time for you masjid or location. Use as a widget or use the short codes and format it as you like.
GoPrayer Developer Profile
3 plugins · 450 total installs
How We Detect GoPrayer
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-prayers-request/assets/css/pray-style.css/wp-content/plugins/wp-prayers-request/assets/js/pray-script.js/wp-content/plugins/wp-prayers-request/assets/js/pray-script.jswp-prayers-request/assets/css/pray-style.css?ver=wp-prayers-request/assets/js/pray-script.js?ver=HTML / DOM Fingerprints
[prayers_form][prayers_list][prayers_view]