Is "Prayer Times Companion" on Chrome Web Store Safe to Install?

[email protected] · chrome · v2.2

Never miss a prayer! Get accurate prayer times and Athan notifications for your location, right in your browser. Key Features & Benefits: Accurate Prayer Times: Get precise prayer (Salat) times for Fajr, Dhuhr, Asr, Maghrib, and Isha based on your current location or a manually selected city. Ensures you always know when it's time to pray, wherever you are. Customizable Athan Notifications: Receive timely audio and visual notifications for each prayer, with options to choose your favorite Athan sound. Helps you remember and prepare for prayer without distraction. Multiple Calculation Methods: Supports various Islamic calculation methods (e.g., Muslim World League, ISNA, Umm Al-Qura, Egyptian General Authority of Survey, Hanafi, etc.) to suit your preference. Ensures accurate timings according to your school of thought. Qibla Direction (If applicable): Easily find the direction of the Qibla (Kaaba) from your current location. Helps you orient yourself correctly for prayer. Hijri Date Display: View the current Islamic Hijri date alongside the Gregorian calendar. Keeps you connected with the Islamic calendar. Time Until Next Prayer: See a clear countdown to the next prayer time directly on the extension icon or within the popup. Helps you manage your time and prepare spiritually. Offline Functionality: Once loaded, prayer times can be accessed even without an internet connection (depending on your implementation for calculation/storage). Reliable access, even when offline. User-Friendly Interface: A clean, intuitive design that makes checking prayer times simple and quick. Enhances your daily digital experience." now with new modern style

Risk Assessment

Analyzed
56.26
out of 100
MEDIUM

183 security findings detected across all analyzers

Chrome extension requesting 14 permissions

Severity Breakdown

0
Critical
25
High
158
Medium
0
Low
0
Info

Finding Categories

25
Malware Signatures
4
Network
154
IoC Indicators

YARA Rules Matched

6 rules(25 hits)
postinstall network communication postinstall file download postinstall persistence mechanism postinstall system command postinstall crypto operations postinstall file manipulation

Requested Permissions

14 permissions
activeTab
Medium
storage
Low
alarms
Low
notifications
Low
geolocation
Low
scripting
Low
offscreen
Low
https://api.aladhan.com/*
Low
https://cdn.islamic.network/*
Low
https://fonts.googleapis.com/*
Low
https://fonts.gstatic.com/*
Low
https://www.thonem.com/*
Low
https://www.thonem.com/
Low
*://*.thonem.com/
Low

About This Extension

Never miss a prayer! Get accurate prayer times and Athan notifications for your location, right in your browser. Key Features & Benefits: Accurate Prayer Times: Get precise prayer (Salat) times for Fajr, Dhuhr, Asr, Maghrib, and Isha based on your current location or a manually selected city. Ensures you always know when it's time to pray, wherever you are. Customizable Athan Notifications: Receive timely audio and visual notifications for each prayer, with options to choose your favorite Athan sound. Helps you remember and prepare for prayer without distraction. Multiple Calculation Methods: Supports various Islamic calculation methods (e.g., Muslim World League, ISNA, Umm Al-Qura, Egyptian General Authority of Survey, Hanafi, etc.) to suit your preference. Ensures accurate timings according to your school of thought. Qibla Direction (If applicable): Easily find the direction of the Qibla (Kaaba) from your current location. Helps you orient yourself correctly for prayer. Hijri Date Display: View the current Islamic Hijri date alongside the Gregorian calendar. Keeps you connected with the Islamic calendar. Time Until Next Prayer: See a clear countdown to the next prayer time directly on the extension icon or within the popup. Helps you manage your time and prepare spiritually. Offline Functionality: Once loaded, prayer times can be accessed even without an internet connection (depending on your implementation for calculation/storage). Reliable access, even when offline. User-Friendly Interface: A clean, intuitive design that makes checking prayer times simple and quick. Enhances your daily digital experience." now with new modern style

Detailed Findings

29 total

YARA Rule Matches

6 rules

Indicators of Compromise

Network indicators, suspicious strings, and potential IoCs extracted during analysis

URLs
25
IP Addresses
19
Domains
109
Strings
154

All Indicators · 154

Domain
detected Domain: currentaudio.play

XIOC detected Domain: currentaudio.play

extracted_from_files

Domain
detected Domain: www.w3.org

XIOC detected Domain: www.w3.org

extracted_from_files

URL
detected URL: https://fonts.googleapis.com/*

XIOC detected URL: https://fonts.googleapis.com/*

extracted_from_files

URL
detected URL: https://fonts.gstatic.com/*

XIOC detected URL: https://fonts.gstatic.com/*

extracted_from_files

URL
detected URL: https://www.thonem.com/*

XIOC detected URL: https://www.thonem.com/*

extracted_from_files

URL
detected URL: https://www.thonem.com/

XIOC detected URL: https://www.thonem.com/

extracted_from_files

URL
detected URL: https://getbootstrap.com/)

XIOC detected URL: https://getbootstrap.com/)

extracted_from_files

URL
detected URL: https://github.com/twbs/bootstrap/blob/main/LICENSE)

XIOC detected URL: https://github.com/twbs/bootstrap/blob/main/LICENSE)

extracted_from_files

URL
detected URL: http://www.w3.org/2000/svg'

XIOC detected URL: http://www.w3.org/2000/svg'

extracted_from_files

URL
detected URL: https://api.aladhan.com/v1/timings/$

XIOC detected URL: https://api.aladhan.com/v1/timings/$

extracted_from_files

URL
detected URL: https://cdn.islamic.network/athan/audio/fa-IR/02.mp3',

XIOC detected URL: https://cdn.islamic.network/athan/audio/fa-IR/02.mp3',

extracted_from_files

URL
detected URL: https://cdn.islamic.network/athan/audio/fa-IR/03.mp3'

XIOC detected URL: https://cdn.islamic.network/athan/audio/fa-IR/03.mp3'

extracted_from_files

URL
detected URL: https://www.thonem.com/en/api/prayer_times';

XIOC detected URL: https://www.thonem.com/en/api/prayer_times';

extracted_from_files

Other
detected Email: [email protected]

XIOC detected Email: [email protected]

extracted_from_files

Other
detected Email: [email protected]

XIOC detected Email: [email protected]

extracted_from_files

URL
detected URL: https://www.favicon-generator.org/

XIOC detected URL: https://www.favicon-generator.org/

extracted_from_files

URL
detected URL: https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&display=swap

XIOC detected URL: https://fonts.googleapis.com/css2?family=Inter:wght@400;500;600;700&display=swap

extracted_from_files

URL
detected URL: https://cdn.islamic.network/athan/audio/fa-IR/01.mp3

XIOC detected URL: https://cdn.islamic.network/athan/audio/fa-IR/01.mp3

extracted_from_files

URL
detected URL: https://cdn.islamic.network/athan/audio/fa-IR/02.mp3

XIOC detected URL: https://cdn.islamic.network/athan/audio/fa-IR/02.mp3

extracted_from_files

URL
detected URL: https://cdn.islamic.network/athan/audio/fa-IR/03.mp3

XIOC detected URL: https://cdn.islamic.network/athan/audio/fa-IR/03.mp3

extracted_from_files

Domain
detected Domain: city.country

XIOC detected Domain: city.country

extracted_from_files

Domain
detected Domain: b.name

XIOC detected Domain: b.name

extracted_from_files

Domain
detected Domain: country.name

XIOC detected Domain: country.name

extracted_from_files

Domain
detected Domain: city.name

XIOC detected Domain: city.name

extracted_from_files

Domain
detected Domain: currentprayerobj.name

XIOC detected Domain: currentprayerobj.name

extracted_from_files

Domain
detected Domain: nextprayerobj.name

XIOC detected Domain: nextprayerobj.name

extracted_from_files

Domain
detected Domain: prayer.name

XIOC detected Domain: prayer.name

extracted_from_files

Domain
detected Domain: adhan2.mp

XIOC detected Domain: adhan2.mp

extracted_from_files

Domain
detected Domain: adhan3.mp

XIOC detected Domain: adhan3.mp

extracted_from_files

Domain
detected Domain: adhan4.mp

XIOC detected Domain: adhan4.mp

extracted_from_files

Domain
detected Domain: adhan5.mp

XIOC detected Domain: adhan5.mp

extracted_from_files

Domain
detected Domain: adhan6.mp

XIOC detected Domain: adhan6.mp

extracted_from_files

Domain
detected Domain: logs.map

XIOC detected Domain: logs.map

extracted_from_files

Domain
detected Domain: jsondata.data

XIOC detected Domain: jsondata.data

extracted_from_files

Domain
detected Domain: result.country

XIOC detected Domain: result.country

extracted_from_files

Domain
detected Domain: adhan.mp

XIOC detected Domain: adhan.mp

extracted_from_files

Domain
detected Domain: fonts.gstatic.com

XIOC detected Domain: fonts.gstatic.com

extracted_from_files

Domain
detected Domain: thonem.com

XIOC detected Domain: thonem.com

extracted_from_files

Domain
detected Domain: clients2.google.com

XIOC detected Domain: clients2.google.com

extracted_from_files

Domain
detected Domain: audio.play

XIOC detected Domain: audio.play

extracted_from_files

Domain
detected Domain: prayer-name.next

XIOC detected Domain: prayer-name.next

extracted_from_files

Domain
detected Domain: config.post

XIOC detected Domain: config.post

extracted_from_files

Domain
detected Domain: alarm.name

XIOC detected Domain: alarm.name

extracted_from_files

Domain
detected Domain: alarms.map

XIOC detected Domain: alarms.map

extracted_from_files

Domain
detected Domain: a.name

XIOC detected Domain: a.name

extracted_from_files

Domain
detected Domain: www.thonem.com

XIOC detected Domain: www.thonem.com

extracted_from_files

Domain
detected Domain: nextprayer.name

XIOC detected Domain: nextprayer.name

extracted_from_files

Domain
detected Domain: result.city

XIOC detected Domain: result.city

extracted_from_files

Domain
detected Domain: offcanvas-xxl.show

XIOC detected Domain: offcanvas-xxl.show

extracted_from_files

Domain
detected Domain: offcanvas.show

XIOC detected Domain: offcanvas.show

extracted_from_files

Domain
detected Domain: offcanvas-backdrop.show

XIOC detected Domain: offcanvas-backdrop.show

extracted_from_files

Domain
detected Domain: bootstrap.min.css.map

XIOC detected Domain: bootstrap.min.css.map

extracted_from_files

Domain
detected Domain: api.aladhan.com

XIOC detected Domain: api.aladhan.com

extracted_from_files

Domain
detected Domain: data.data

XIOC detected Domain: data.data

extracted_from_files

Domain
detected Domain: date.now

XIOC detected Domain: date.now

extracted_from_files

Domain
detected Domain: modal.show

XIOC detected Domain: modal.show

extracted_from_files

Domain
detected Domain: modal-backdrop.show

XIOC detected Domain: modal-backdrop.show

extracted_from_files

IP
detected Domain: tooltip.show

XIOC detected Domain: tooltip.show

extracted_from_files

Domain
detected Domain: offcanvas-sm.show

XIOC detected Domain: offcanvas-sm.show

extracted_from_files

Domain
detected Domain: offcanvas-md.show

XIOC detected Domain: offcanvas-md.show

extracted_from_files

Domain
detected Domain: offcanvas-lg.show

XIOC detected Domain: offcanvas-lg.show

extracted_from_files

Domain
detected Domain: offcanvas-xl.show

XIOC detected Domain: offcanvas-xl.show

extracted_from_files

Domain
detected Domain: form-select.is

XIOC detected Domain: form-select.is

extracted_from_files

Domain
detected Domain: form-control-color.is

XIOC detected Domain: form-control-color.is

extracted_from_files

Domain
detected Domain: form-check-input.is

XIOC detected Domain: form-check-input.is

extracted_from_files

Domain
detected Domain: btn.show

XIOC detected Domain: btn.show

extracted_from_files

Domain
detected Domain: dropdown-menu.show

XIOC detected Domain: dropdown-menu.show

extracted_from_files

Domain
detected Domain: nav-item.show

XIOC detected Domain: nav-item.show

extracted_from_files

Domain
detected Domain: nav-link.show

XIOC detected Domain: nav-link.show

extracted_from_files

Domain
detected Domain: 02.mp

XIOC detected Domain: 02.mp

extracted_from_files

Domain
detected Domain: 03.mp

XIOC detected Domain: 03.mp

extracted_from_files

Domain
detected Domain: getbootstrap.com

XIOC detected Domain: getbootstrap.com

extracted_from_files

URL
detected URL: https://api.aladhan.com/*

XIOC detected URL: https://api.aladhan.com/*

extracted_from_files

URL
detected URL: http://www.w3.org/2000/svg

XIOC detected URL: http://www.w3.org/2000/svg

extracted_from_files

IP
detected IP: 9::

XIOC detected IP: 9::

extracted_from_files

Domain
detected Domain: textarea.form-control.is

XIOC detected Domain: textarea.form-control.is

extracted_from_files

Domain
detected Domain: edyr.uk

XIOC detected Domain: edyr.uk

extracted_from_files

Domain
detected Domain: f.ma

XIOC detected Domain: f.ma

extracted_from_files

URL
detected URL: https://cdn.islamic.network/*

XIOC detected URL: https://cdn.islamic.network/*

extracted_from_files

Domain
detected Domain: i.vg

XIOC detected Domain: i.vg

extracted_from_files

Domain
detected Domain: gt.sk

XIOC detected Domain: gt.sk

extracted_from_files

Domain
detected Domain: cdn.islamic.network

XIOC detected Domain: cdn.islamic.network

extracted_from_files

Domain
detected Domain: 01.mp

XIOC detected Domain: 01.mp

extracted_from_files

Domain
detected Domain: x.th

XIOC detected Domain: x.th

extracted_from_files

Domain
detected Domain: ĕ.gb

XIOC detected Domain: ĕ.gb

extracted_from_files

Domain
detected Domain: ik1.ar

XIOC detected Domain: ik1.ar

extracted_from_files

Domain
detected Domain: f.uk

XIOC detected Domain: f.uk

extracted_from_files

Domain
detected Domain: 7e.bm

XIOC detected Domain: 7e.bm

extracted_from_files

Domain
detected Domain: l.ve

XIOC detected Domain: l.ve

extracted_from_files

Domain
detected Domain: aɮi8o.hr

XIOC detected Domain: aɮi8o.hr

extracted_from_files

Domain
detected Domain: ij.gt

XIOC detected Domain: ij.gt

extracted_from_files

Domain
detected Domain: w.bn

XIOC detected Domain: w.bn

extracted_from_files

Domain
detected Domain: 2.ee

XIOC detected Domain: 2.ee

extracted_from_files

Domain
detected Domain: m.jm

XIOC detected Domain: m.jm

extracted_from_files

Domain
detected Domain: f.ua

XIOC detected Domain: f.ua

extracted_from_files

Domain
detected Domain: n.mr

XIOC detected Domain: n.mr

extracted_from_files

Domain
detected Domain: fh.au

XIOC detected Domain: fh.au

extracted_from_files

Domain
detected Domain: f.cd

XIOC detected Domain: f.cd

extracted_from_files

Domain
detected Domain: ac.pm

XIOC detected Domain: ac.pm

extracted_from_files

Domain
detected Domain: dl-.mu

XIOC detected Domain: dl-.mu

extracted_from_files

Domain
detected Domain: tagwww.islamcan.com

XIOC detected Domain: tagwww.islamcan.com

extracted_from_files

Domain
detected Domain: ƞy.nl

XIOC detected Domain: ƞy.nl

extracted_from_files

Domain
detected Domain: 3.gb

XIOC detected Domain: 3.gb

extracted_from_files

Domain
detected Domain: k.lr

XIOC detected Domain: k.lr

extracted_from_files

Domain
detected Domain: qg.gl

XIOC detected Domain: qg.gl

extracted_from_files

Domain
detected Domain: if.gl

XIOC detected Domain: if.gl

extracted_from_files

Domain
detected Domain: kh.gl

XIOC detected Domain: kh.gl

extracted_from_files

Domain
detected Domain: id.gl

XIOC detected Domain: id.gl

extracted_from_files

Domain
detected Domain: me.gl

XIOC detected Domain: me.gl

extracted_from_files

Domain
detected Domain: o.ml

XIOC detected Domain: o.ml

extracted_from_files

Domain
detected Domain: kd.gl

XIOC detected Domain: kd.gl

extracted_from_files

Domain
detected Domain: 7uw6.nab

XIOC detected Domain: 7uw6.nab

extracted_from_files

Domain
detected Domain: se.hk

XIOC detected Domain: se.hk

extracted_from_files

Domain
detected Domain: g.mx

XIOC detected Domain: g.mx

extracted_from_files

Domain
detected Domain: do.jm

XIOC detected Domain: do.jm

extracted_from_files

Domain
detected Domain: h.gt

XIOC detected Domain: h.gt

extracted_from_files

Domain
detected Domain: c0.uz

XIOC detected Domain: c0.uz

extracted_from_files

Domain
detected Domain: mb.gl

XIOC detected Domain: mb.gl

extracted_from_files

Domain
detected Domain: k.tk

XIOC detected Domain: k.tk

extracted_from_files

Domain
detected Domain: 21.kn

XIOC detected Domain: 21.kn

extracted_from_files

Domain
detected Domain: ni.lc

XIOC detected Domain: ni.lc

extracted_from_files

Domain
detected Domain: a.jp

XIOC detected Domain: a.jp

extracted_from_files

Domain
detected Domain: i.tk

XIOC detected Domain: i.tk

extracted_from_files

Domain
detected Domain: www.islamcan.com

XIOC detected Domain: www.islamcan.com

extracted_from_files

Domain
detected Domain: t.al

XIOC detected Domain: t.al

extracted_from_files

IP
detected IP: ed::

XIOC detected IP: ed::

extracted_from_files

IP
detected IP: e::af

XIOC detected IP: e::af

extracted_from_files

IP
detected IP: e::bef

XIOC detected IP: e::bef

extracted_from_files

Domain
detected Domain: www.favicon-generator.org

XIOC detected Domain: www.favicon-generator.org

extracted_from_files

Domain
detected Domain: fonts.googleapis.com

XIOC detected Domain: fonts.googleapis.com

extracted_from_files

Domain
detected Domain: brightery.com

XIOC detected Domain: brightery.com

extracted_from_files

Domain
detected Domain: adhan1.mp

XIOC detected Domain: adhan1.mp

extracted_from_files

IP
detected IP: ::ffc

XIOC detected IP: ::ffc

extracted_from_files

IP
detected IP: e::2

XIOC detected IP: e::2

extracted_from_files

IP
detected IP: 7::

XIOC detected IP: 7::

extracted_from_files

IP
detected IP: ::af

XIOC detected IP: ::af

extracted_from_files

IP
detected IP: ::bef

XIOC detected IP: ::bef

extracted_from_files

IP
detected IP: ::f

XIOC detected IP: ::f

extracted_from_files

IP
detected IP: e::

XIOC detected IP: e::

extracted_from_files

IP
detected IP: ::

XIOC detected IP: ::

extracted_from_files

IP
detected IP: d::

XIOC detected IP: d::

extracted_from_files

IP
detected IP: 8::

XIOC detected IP: 8::

extracted_from_files

IP
detected IP: ::d

XIOC detected IP: ::d

extracted_from_files

IP
detected IP: ::7

XIOC detected IP: ::7

extracted_from_files

IP
detected IP: ::b

XIOC detected IP: ::b

extracted_from_files

IP
detected IP: 0e::

XIOC detected IP: 0e::

extracted_from_files

URL
detected URL: https://www.thonem.com/en/api/prayer_times/cities?country=$

XIOC detected URL: https://www.thonem.com/en/api/prayer_times/cities?country=$

extracted_from_files

URL
detected URL: https://www.thonem.com/en/api/prayer_times/countries?limit=500');

XIOC detected URL: https://www.thonem.com/en/api/prayer_times/countries?limit=500');

extracted_from_files

URL
detected URL: https://clients2.google.com/service/update2/crx

XIOC detected URL: https://clients2.google.com/service/update2/crx

extracted_from_files

URL
detected URL: https://cdn.islamic.network;

XIOC detected URL: https://cdn.islamic.network;

extracted_from_files

URL
detected URL: https://fonts.gstatic.com;

XIOC detected URL: https://fonts.gstatic.com;

extracted_from_files

URL
detected URL: https://fonts.googleapis.com;

XIOC detected URL: https://fonts.googleapis.com;

extracted_from_files

Domain
detected Domain: form-control.is

XIOC detected Domain: form-control.is

extracted_from_files

Domain
detected Domain: github.com

XIOC detected Domain: github.com

extracted_from_files

Security Analysis Summary

Security Analysis Overview

Prayer Times Companion is a Chrome Web Store extension published by [email protected]. Version 2.2 has been analyzed by the Risky Plugins security platform, receiving a risk score of 56.26/100 (MEDIUM risk) based on 183 security findings.

Risk Assessment

This extension presents moderate security risk. Several findings were detected that may warrant attention. Users should carefully review the permissions and findings before installation.

Findings Breakdown

  • High: 25 finding(s)
  • Medium: 158 finding(s)

What Was Analyzed

The security assessment covers multiple analysis categories:

  • Malware Detection: YARA rule matching against 2,400+ malware signatures
  • Secret Detection: Scanning for exposed API keys, tokens, and credentials
  • Static Analysis: Code-level security analysis for common vulnerability patterns
  • Network Analysis: Detection of suspicious network communications and endpoints
  • Obfuscation Detection: Identification of code obfuscation techniques

Developer Information

Prayer Times Companion is published by [email protected] on the Chrome Web Store marketplace. The extension has approximately 9 users.

Recommendation

Exercise caution with this extension. Review the detailed findings and ensure the requested permissions align with the extension's stated functionality before installation.

Frequently Asked Questions