Anton Featured Events Manager Security & Risk Analysis

wordpress.org/plugins/4nton-featured-events-manager

Anton Featured Events Manager is an addons of Events Manager created By Marcus Sykes.

0 active installs v1.0.4 PHP + WP 4.4+ Updated Unknown
eventsfeaturedmanagerwdeswidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Anton Featured Events Manager Safe to Use in 2026?

Generally Safe

Score 100/100

Anton Featured Events Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 4nton-featured-events-manager plugin, at version 1.0.4, exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries, properly escaping all output, and not performing any file operations or external HTTP requests. The absence of known vulnerabilities in its history is also a positive indicator, suggesting a generally well-maintained codebase.

However, significant security concerns arise from the static analysis. The plugin exposes two AJAX handlers, both of which lack authentication checks. This represents a considerable attack surface that could be exploited by unauthenticated users. The complete absence of nonce checks and capability checks on these entry points further exacerbates this risk, as any user, authenticated or not, can trigger these handlers.

While the taint analysis shows no critical or high severity vulnerabilities, the lack of authentication on AJAX endpoints is a glaring omission. The plugin's vulnerability history is clean, which is good, but this does not mitigate the immediate risks identified in the static analysis. The overall risk is elevated due to the unprotected AJAX endpoints, which are primary targets for malicious activity. A balanced conclusion is that while the plugin avoids common pitfalls like raw SQL or unescaped output, its security is significantly compromised by the direct exposure of critical functionalities via unauthenticated AJAX calls.

Key Concerns

  • AJAX handlers without authentication
  • AJAX handlers without nonce checks
  • AJAX handlers without capability checks
Vulnerabilities
None known

Anton Featured Events Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Anton Featured Events Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface
2 unprotected

Anton Featured Events Manager Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_anton_fem_ajaxanton-featured-events-manager.php:57
noprivwp_ajax_anton_fem_ajaxanton-featured-events-manager.php:58

Shortcodes 1

[anton-fem-widget] anton-featured-events-manager.php:62
WordPress Hooks 11
actionadmin_print_stylesanton-featured-events-manager.php:50
actionadmin_print_scriptsanton-featured-events-manager.php:51
actionwp_enqueue_scriptsanton-featured-events-manager.php:52
actionadmin_initanton-featured-events-manager.php:53
actionadmin_menuanton-featured-events-manager.php:54
filtermanage_event_posts_columnsanton-featured-events-manager.php:55
actionmanage_event_posts_custom_columnanton-featured-events-manager.php:56
actionsave_postanton-featured-events-manager.php:59
actionadd_meta_boxesanton-featured-events-manager.php:60
actionwidgets_initanton-featured-events-manager.php:61
actionplugins_loadedanton-featured-events-manager.php:260
Maintenance & Trust

Anton Featured Events Manager Maintenance & Trust

Maintenance Signals

WordPress version tested5.0.25
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Anton Featured Events Manager Developer Profile

Anthony Carbon

5 plugins · 30 total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Anton Featured Events Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/4nton-featured-events-manager/assets/css/admin.css/wp-content/plugins/4nton-featured-events-manager/assets/js/admin.js/wp-content/plugins/4nton-featured-events-manager/assets/js/bxslider.min.js/wp-content/plugins/4nton-featured-events-manager/assets/js/script.js
Script Paths
assets/js/admin.jsassets/js/bxslider.min.jsassets/js/script.js
Version Parameters
4nton-featured-events-manager/assets/css/admin.css?ver=4nton-featured-events-manager/assets/js/admin.js?ver=4nton-featured-events-manager/assets/js/bxslider.min.js?ver=4nton-featured-events-manager/assets/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
anton-fem-featuredanton-fem-featured-activeanton-fem-featured-not-activeanton-fem-img-1anton-fem-img-2
Data Attributes
data-id
JS Globals
anton_fem
FAQ

Frequently Asked Questions about Anton Featured Events Manager