
Add infos to The Events Calendar Security & Risk Analysis
wordpress.org/plugins/add-infos-to-the-events-calendar“Add infos to The Events Calendar” provides a shortcode block to single events for The Events Calendar Free Plugin (by MODERN TRIBE)
Is Add infos to The Events Calendar Safe to Use in 2026?
Generally Safe
Score 99/100Add infos to The Events Calendar has a strong security track record. Known vulnerabilities have been patched promptly.
The 'add-infos-to-the-events-calendar' plugin version 1.5.2 exhibits a generally good security posture with several strengths. The absence of dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests is commendable. Furthermore, the plugin has no known unpatched vulnerabilities, and the single past medium severity vulnerability was addressed. The limited attack surface, consisting of one shortcode with no direct indication of being unprotected, also contributes positively to its security.
However, there are areas for improvement. A significant concern is the output escaping, where only 65% of outputs are properly escaped. This leaves a considerable portion of user-generated or dynamically generated content potentially vulnerable to Cross-Site Scripting (XSS) attacks. While taint analysis shows no current critical or high severity flows, the incomplete output escaping means that even minor XSS vulnerabilities could be present and exploitable. The complete lack of nonce checks, especially for any AJAX handlers that might exist or be introduced in future updates, is another potential weakness.
In conclusion, while the plugin has taken proactive steps in secure coding practices and managing its vulnerability history, the unaddressed output escaping is a notable risk. Future development should prioritize ensuring all outputs are properly sanitized to mitigate XSS risks. The absence of nonce checks also warrants attention for robust security, particularly if the plugin interacts with the front-end through JavaScript.
Key Concerns
- Significant portion of outputs not properly escaped
- No nonce checks implemented
Add infos to The Events Calendar Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Add infos to the events calendar <= 1.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Add infos to The Events Calendar Code Analysis
Output Escaping
Add infos to The Events Calendar Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Add infos to The Events Calendar Maintenance & Trust
Maintenance Signals
Community Trust
Add infos to The Events Calendar Alternatives
The Events Calendar Shortcode & Block
the-events-calendar-shortcode
Add shortcode, block, Elementor and Bricks functionality to The Events Calendar Plugin, so you can easily list and promote your events anywhere.
Events Shortcodes For The Events Calendar
template-events-calendar
Add The Events Calendar shortcode or Gutenberg block to show upcoming events list with event details on any WordPress page using smart event filters.
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
contact-form-plugin
The most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
Forget About Shortcode Buttons
forget-about-shortcode-buttons
A visual way to add CSS buttons in the rich text editor and to your themes.
Events Widgets For Elementor And The Events Calendar
events-widgets-for-elementor-and-the-events-calendar
The Events Calendar Elementor widgets help you manage and display an upcoming events list with date, time, venue and event ticket booking details.
Add infos to The Events Calendar Developer Profile
11 plugins · 340 total installs
How We Detect Add infos to The Events Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/add-infos-to-the-events-calendar/assets/css/ait_style_fuss.css/add-infos-to-the-events-calendar/assets/css/ait_style_fuss.css?ver=/wp-content/plugins/add-infos-to-the-events-calendar/assets/css/ait_style_fuss.css?ver=HTML / DOM Fingerprints
fuss_button-absatzfuss_button-beitragTODO remove and replace with translate.wordpress.org.TODO using hooks for internal things.data-fs_hintergrundfarbe_buttondata-fs_vordergrundfarbe_buttondata-fs_hover_hintergrundfarbe_buttondata-fs_hover_vordergrundfarbe_buttondata-fs_runder_button<p class="fuss_button-absatz"><a class="fuss_button-beitrag" href=<p class="fuss_button-absatz"><em><p class="fuss_button-absatz"><strong><p class="fuss_button-absatz"><a class="fuss_button-beitrag" href=