
Zmanim WP Security & Risk Analysis
wordpress.org/plugins/zmanim-wpThis plugin lets you configure a variety of halachic time calculations and add them via shortcodes.
Is Zmanim WP Safe to Use in 2026?
Generally Safe
Score 100/100Zmanim WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The zmanim-wp plugin v2.4.0 presents a strong security posture based on the provided static analysis. The absence of any detected dangerous functions, raw SQL queries, or significant unescaped output is commendable. The plugin also has a clean vulnerability history with no known CVEs, suggesting a commitment to secure coding practices over time.
However, the analysis highlights a complete lack of capability checks and nonce checks across all entry points. While there are currently no exposed entry points in this version, this absence represents a significant potential risk. If any AJAX handlers, REST API routes, or shortcodes were to be introduced in future versions without proper authorization mechanisms, it could lead to severe vulnerabilities. The presence of file operations without explicit mention of their sanitization also warrants attention, although no specific issues were flagged in the taint analysis.
In conclusion, the plugin exhibits good fundamental coding practices. The lack of exploitable vulnerabilities and the absence of dangerous code constructs are major strengths. The primary concern is the complete reliance on the absence of an attack surface for security, rather than implementing robust authorization and input validation for potential future extensions. This makes the plugin's security heavily dependent on future development decisions.
Key Concerns
- No capability checks detected
- No nonce checks detected
- File operations present, security not specified
Zmanim WP Security Vulnerabilities
Zmanim WP Code Analysis
Output Escaping
Zmanim WP Attack Surface
WordPress Hooks 6
Maintenance & Trust
Zmanim WP Maintenance & Trust
Maintenance Signals
Community Trust
Zmanim WP Alternatives
No alternatives data available yet.
Zmanim WP Developer Profile
3 plugins · 70 total installs
How We Detect Zmanim WP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zmanim-wp/zmanim-wp-style.css/wp-content/plugins/zmanim-wp/zmanim-wp-script.js/wp-content/plugins/zmanim-wp/zmanim-wp-script.jszmanim-wp/zmanim-wp-style.css?ver=zmanim-wp/zmanim-wp-script.js?ver=HTML / DOM Fingerprints
[zman_location][zman_lat][zman_long][zman_tzone]