Zmanim WP Security & Risk Analysis

wordpress.org/plugins/zmanim-wp

This plugin lets you configure a variety of halachic time calculations and add them via shortcodes.

0 active installs v2.4.0 PHP + WP + Updated Feb 24, 2026
time-zmanim-jewish
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Zmanim WP Safe to Use in 2026?

Generally Safe

Score 100/100

Zmanim WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The zmanim-wp plugin v2.4.0 presents a strong security posture based on the provided static analysis. The absence of any detected dangerous functions, raw SQL queries, or significant unescaped output is commendable. The plugin also has a clean vulnerability history with no known CVEs, suggesting a commitment to secure coding practices over time.

However, the analysis highlights a complete lack of capability checks and nonce checks across all entry points. While there are currently no exposed entry points in this version, this absence represents a significant potential risk. If any AJAX handlers, REST API routes, or shortcodes were to be introduced in future versions without proper authorization mechanisms, it could lead to severe vulnerabilities. The presence of file operations without explicit mention of their sanitization also warrants attention, although no specific issues were flagged in the taint analysis.

In conclusion, the plugin exhibits good fundamental coding practices. The lack of exploitable vulnerabilities and the absence of dangerous code constructs are major strengths. The primary concern is the complete reliance on the absence of an attack surface for security, rather than implementing robust authorization and input validation for potential future extensions. This makes the plugin's security heavily dependent on future development decisions.

Key Concerns

  • No capability checks detected
  • No nonce checks detected
  • File operations present, security not specified
Vulnerabilities
None known

Zmanim WP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Zmanim WP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
289 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped293 total outputs
Attack Surface

Zmanim WP Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_menuzmanim-wp.php:40
actionadmin_initzmanim-wp.php:97
actionadmin_initzmanim-wp.php:98
actionadmin_initzmanim-wp.php:99
actionadmin_initzmanim-wp.php:100
filterthe_contentzmanim-wp.php:1465
Maintenance & Trust

Zmanim WP Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 24, 2026
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

Zmanim WP Alternatives

No alternatives data available yet.

Developer Profile

Zmanim WP Developer Profile

adatosystems

3 plugins · 70 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Zmanim WP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zmanim-wp/zmanim-wp-style.css/wp-content/plugins/zmanim-wp/zmanim-wp-script.js
Script Paths
/wp-content/plugins/zmanim-wp/zmanim-wp-script.js
Version Parameters
zmanim-wp/zmanim-wp-style.css?ver=zmanim-wp/zmanim-wp-script.js?ver=

HTML / DOM Fingerprints

Shortcode Output
[zman_location][zman_lat][zman_long][zman_tzone]
FAQ

Frequently Asked Questions about Zmanim WP