Xhanch – My Prayer Time Security & Risk Analysis

wordpress.org/plugins/xhanch-my-prayer-time

Xhanch - My Prayer Time displays Moslem/Islamic prayer time table based on visitor's IP (daily and monthly).

10 active installs v1.0.2 PHP + WP 2.3+ Updated Sep 4, 2016
codecontentsidebarwidgetxhanch
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Xhanch – My Prayer Time Safe to Use in 2026?

Generally Safe

Score 85/100

Xhanch – My Prayer Time has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "xhanch-my-prayer-time" plugin v1.0.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding SQL injection vulnerabilities through the exclusive use of prepared statements and has no known CVEs, indicating a relatively clean history. However, significant concerns arise from the static analysis. The plugin fails to properly escape any of its outputs, which poses a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis reveals two flows with unsanitized paths, although their severity is not explicitly stated as critical or high, the presence of such flows warrants attention. The absence of any nonce or capability checks on its entry points, combined with the presence of file operations and external HTTP requests, creates potential avenues for unauthorized actions or data leakage if these operations are not handled securely within the plugin's logic.

Key Concerns

  • No output escaping
  • Unsanitized paths in taint flows
  • No capability checks
  • No nonce checks
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

Xhanch – My Prayer Time Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Xhanch – My Prayer Time Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
21
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped21 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
xhanch_my_prayer_time_get_client_info (xhanch_my_prayer_time.function.php:70)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Xhanch – My Prayer Time Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterthe_contentxhanch_my_prayer_time.php:234
actionplugins_loadedxhanch_my_prayer_time.php:236
actionwp_print_scriptsxhanch_my_prayer_time.php:246
actionwp_print_stylesxhanch_my_prayer_time.php:251
Maintenance & Trust

Xhanch – My Prayer Time Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedSep 4, 2016
PHP min version
Downloads10K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Xhanch – My Prayer Time Developer Profile

xhanch_studio

3 plugins · 220 total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
3462 days
View full developer profile
Detection Fingerprints

How We Detect Xhanch – My Prayer Time

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xhanch-my-prayer-time/xhanch_my_prayer_time.css/wp-content/plugins/xhanch-my-prayer-time/xhanch_my_prayer_time.js
Script Paths
/wp-content/plugins/xhanch-my-prayer-time/xhanch_my_prayer_time.js
Version Parameters
xhanch-my-prayer-time/xhanch_my_prayer_time.css?ver=xhanch-my-prayer-time/xhanch_my_prayer_time.js?ver=

HTML / DOM Fingerprints

CSS Classes
xhanch_my_prayer_time_monthlyajax_progressajax_message
HTML Comments
<!--<tr> <td width="50px">Country</td> <td>--><!--<tr> <td>City</td> <td>--><!--<tr> <td width="50px">Country</td> <td>--><!--<tr> <td>City</td> <td>-->+1 more
Data Attributes
id="xhanch_my_prayer_time_page_date_mm"id="xhanch_my_prayer_time_page_date_yy"id="xhanch_my_prayer_time_table"class="ajax_sct"id="sct_ajax_xhanch_my_prayer_time_page_time_prg"class="ajax_progress"+17 more
JS Globals
ajax_sct_regxhanch_my_prayer_time_page_time_loadxhanch_my_prayer_time_widget_time_load
Shortcode Output
<div id="xhanch_my_prayer_time_table">
FAQ

Frequently Asked Questions about Xhanch – My Prayer Time