
Ajax Archive Calendar Security & Risk Analysis
wordpress.org/plugins/ajax-archive-calendarAjax Archive Calendar .
Is Ajax Archive Calendar Safe to Use in 2026?
Generally Safe
Score 100/100Ajax Archive Calendar has a strong security track record. Known vulnerabilities have been patched promptly.
The ajax-archive-calendar plugin exhibits a mixed security posture. While it demonstrates strengths in its SQL handling and output escaping, significant concerns arise from its attack surface and taint analysis results. The presence of two AJAX handlers without authentication checks represents a direct entry point for unauthenticated users, which is a considerable risk. Furthermore, the taint analysis revealing two flows with unsanitized paths, classified as high severity, directly indicates potential vulnerabilities where attacker-controlled input might be processed insecurely. Although the plugin has a history of one medium CVE related to Cross-site Scripting, which is currently patched, the static analysis suggests a latent risk of similar vulnerabilities due to the unsanitized input flows. The lack of any nonce checks on the unprotected AJAX handlers is a critical omission that exacerbates the risk posed by the unauthenticated entry points. Overall, while the plugin avoids common pitfalls like raw SQL queries and external requests, the identified unauthenticated AJAX handlers and high-severity taint flows necessitate careful review and remediation.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- Missing nonce checks on AJAX
- Medium vulnerability in history
Ajax Archive Calendar Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Ajax Archive Calendar <= 2.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Ajax Archive Calendar Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Ajax Archive Calendar Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Ajax Archive Calendar Maintenance & Trust
Maintenance Signals
Community Trust
Ajax Archive Calendar Alternatives
WP FullCalendar
wp-fullcalendar
Uses the FullCalendar library to create a stunning calendar view of events, posts and other custom post types
Resource Booking and Availability Calendar
resource-booking-and-availability-calendar
Resource Availability & Booking Calendar, wordpress plugin allows you to treat each post as a resource and enables booking of the resource.
Events Search For The Events Calendar
events-search-addon-for-the-events-calendar
Adds an AJAX-based events search bar on any page via shortcode to quickly find any upcoming event created with The Events Calendar plugin.
AJAX Calendar
ajax-calendar
AJAX Calendar is a plugin that will display an AJAXified WordPress calendar.
Eventful for Elementor – Events Showcase For The Events Calendar
eventful-for-elementor
Seamlessly showcase events from The Events Calendar in Elementor with customizable widgets and dynamic layouts.
Ajax Archive Calendar Developer Profile
3 plugins · 1K total installs
How We Detect Ajax Archive Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ajax-archive-calendar/ajax-archive-calendar.phpHTML / DOM Fingerprints
ajax-archive-calendar-wrapaac-headeraac-prevaac-nextaac-titleaac-calendar-wrapperaac-month-year-changeraac-year-select+12 moredata-current-yeardata-current-monthdata-post-typeajax_archive_calendar_params[ajax_archive_calendar