
WP-Shabbat Security & Risk Analysis
wordpress.org/plugins/wp-shabbatClose site or display popup message on Shabbat and Holidays by identifying the address of the user IP and close to 40 km
Is WP-Shabbat Safe to Use in 2026?
Generally Safe
Score 85/100WP-Shabbat has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-shabbat v2.3 plugin exhibits a generally good security posture with no recorded vulnerabilities or known CVEs, suggesting a history of stable and secure development. The static analysis further reinforces this, showing no dangerous functions, no external HTTP requests, and all SQL queries utilizing prepared statements. However, there are significant areas of concern regarding output escaping and a lack of authorization checks. While the attack surface is reported as zero, the low percentage of properly escaped output (20%) combined with zero capability checks indicates a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, though limited in scope, reveals flows with unsanitized paths, which, when coupled with insufficient output escaping and authorization, could potentially be exploited. The absence of nonce checks and capability checks on any entry points, despite the reported zero attack surface, is a critical oversight that contradicts the initial assessment and suggests a potential underreporting or a misunderstanding of what constitutes an attack surface in the provided data. The plugin's strengths lie in its SQL handling and lack of known CVEs, but these are overshadowed by the potential for XSS and unauthorized execution due to inadequate output sanitization and authorization mechanisms.
Key Concerns
- Low percentage of properly escaped output
- Lack of capability checks on entry points
- Taint flows with unsanitized paths
- Lack of nonce checks on entry points
WP-Shabbat Security Vulnerabilities
WP-Shabbat Code Analysis
Output Escaping
Data Flow Analysis
WP-Shabbat Attack Surface
WordPress Hooks 11
Maintenance & Trust
WP-Shabbat Maintenance & Trust
Maintenance Signals
Community Trust
WP-Shabbat Alternatives
Holy Day Off
holy-day-off
The #1 Shabbat & Jewish holiday plugin for WordPress. Automatically close your WooCommerce store on schedule. Set your city once, rest every week.
Alligator Popup
alligator-popup
Add popups to your site. Add links to pages/posts via a shortcode which will be opened in a popup browser window.
Beckin Maintenance Mode
beckin-maintenance-mode
A simple & lightweight, SEO-safe maintenance mode: 503 header + Retry-After, custom message, and admin bypass.
Alligator Menu Popup
alligator-menu-popup
Add the 'mpopup' class to a menu item in a custom menu to open the target in a popup Window.
Shamor
shamor
Redirect user out of your site on Shabbat and Holiday.
WP-Shabbat Developer Profile
4 plugins · 50 total installs
How We Detect WP-Shabbat
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-shabbat/css/wp-shabbat.css/wp-content/plugins/wp-shabbat/js/wp-shabbat.jswp-shabbat/css/wp-shabbat.css?ver=wp-shabbat/js/wp-shabbat.js?ver=HTML / DOM Fingerprints
wp-shabbat-messagedata-wp-shabbat-geo-messagewpShabbat