
Xhanch – My Prayer Time Security & Risk Analysis
wordpress.org/plugins/xhanch-my-prayer-timeXhanch - My Prayer Time displays Moslem/Islamic prayer time table based on visitor's IP (daily and monthly).
Is Xhanch – My Prayer Time Safe to Use in 2026?
Generally Safe
Score 85/100Xhanch – My Prayer Time has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "xhanch-my-prayer-time" plugin v1.0.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding SQL injection vulnerabilities through the exclusive use of prepared statements and has no known CVEs, indicating a relatively clean history. However, significant concerns arise from the static analysis. The plugin fails to properly escape any of its outputs, which poses a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis reveals two flows with unsanitized paths, although their severity is not explicitly stated as critical or high, the presence of such flows warrants attention. The absence of any nonce or capability checks on its entry points, combined with the presence of file operations and external HTTP requests, creates potential avenues for unauthorized actions or data leakage if these operations are not handled securely within the plugin's logic.
Key Concerns
- No output escaping
- Unsanitized paths in taint flows
- No capability checks
- No nonce checks
- File operations present
- External HTTP requests present
Xhanch – My Prayer Time Security Vulnerabilities
Xhanch – My Prayer Time Code Analysis
Output Escaping
Data Flow Analysis
Xhanch – My Prayer Time Attack Surface
WordPress Hooks 4
Maintenance & Trust
Xhanch – My Prayer Time Maintenance & Trust
Maintenance Signals
Community Trust
Xhanch – My Prayer Time Alternatives
Xhanch – My Quote
xhanch-my-quote
Xhanch - My Quote shows a random quote with provided predefined quotes or your own collections.
Content Blocks (Custom Post Widget)
custom-post-widget
This plugin enables you to edit and display Content Blocks in a sidebar widget or using a shortcode.
Disable Author Pages
disable-author-pages
Disable the author pages
Reusable Content Blocks
reusable-content-blocks
Reusable Content Blocks plugin allows you to insert contents (pages, posts, custom post types) created with WPBakery Page Builder into other contents, …
Duplicate Widget
duplicate-widget
A widget that can act as a duplicate of another widget (for synchronized use in another sidebar)
Xhanch – My Prayer Time Developer Profile
3 plugins · 220 total installs
How We Detect Xhanch – My Prayer Time
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/xhanch-my-prayer-time/xhanch_my_prayer_time.css/wp-content/plugins/xhanch-my-prayer-time/xhanch_my_prayer_time.js/wp-content/plugins/xhanch-my-prayer-time/xhanch_my_prayer_time.jsxhanch-my-prayer-time/xhanch_my_prayer_time.css?ver=xhanch-my-prayer-time/xhanch_my_prayer_time.js?ver=HTML / DOM Fingerprints
xhanch_my_prayer_time_monthlyajax_progressajax_message<!--<tr>
<td width="50px">Country</td>
<td>--><!--<tr>
<td>City</td>
<td>--><!--<tr>
<td width="50px">Country</td>
<td>--><!--<tr>
<td>City</td>
<td>-->+1 moreid="xhanch_my_prayer_time_page_date_mm"id="xhanch_my_prayer_time_page_date_yy"id="xhanch_my_prayer_time_table"class="ajax_sct"id="sct_ajax_xhanch_my_prayer_time_page_time_prg"class="ajax_progress"+17 moreajax_sct_regxhanch_my_prayer_time_page_time_loadxhanch_my_prayer_time_widget_time_load<div id="xhanch_my_prayer_time_table">