
Calendar Archives Security & Risk Analysis
wordpress.org/plugins/calendar-archivesCalendar Archives is a visualization plugin for your WordPress site which creates yearly calendar for your posts.
Is Calendar Archives Safe to Use in 2026?
Generally Safe
Score 85/100Calendar Archives has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "calendar-archives" v3.1 plugin exhibits a mixed security posture. While it boasts a small attack surface and no known CVEs, its code analysis reveals significant security concerns. Notably, 100% of its SQL queries are not using prepared statements, presenting a high risk of SQL injection vulnerabilities. Furthermore, all identified outputs are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities. The taint analysis also indicates two flows with unsanitized paths, classified as high severity, further emphasizing potential injection risks.
The absence of known vulnerabilities is a positive sign, suggesting a potentially well-maintained codebase or a lack of public exploitation. However, this must be weighed against the identified code quality issues. The lack of capability and nonce checks, combined with the direct use of SQL and unescaped output, creates inherent weaknesses that could be easily exploited if an attacker can trigger the tainted code paths. The plugin's static analysis paints a concerning picture regarding its internal security practices, despite its clean vulnerability history.
Key Concerns
- SQL queries not using prepared statements
- Output escaping not properly implemented
- Taint flows with unsanitized paths (high severity)
- No nonce checks
- No capability checks
Calendar Archives Security Vulnerabilities
Calendar Archives Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Calendar Archives Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Calendar Archives Maintenance & Trust
Maintenance Signals
Community Trust
Calendar Archives Alternatives
ARCW Popover Addon
arcw-popover-addon
Popover Addon for Archives Calendar Widget
Compact Monthly Archive
compact-monthly-archive-widget
Show a monthly archive list in a compact format - one letter per month.
The Events Calendar
the-events-calendar
The Events Calendar: #1 calendar plugin for WordPress. Create/manage events (virtual too!) on your site with the free plugin.
LatePoint – Calendar Booking Plugin for Appointments and Events
latepoint
Optimize your appointment scheduling with our plugin. Sync calendars, automate reminders, and keep your bookings organized.
Online Scheduling and Appointment Booking System – Bookly
bookly-responsive-appointment-booking-tool
Appointment booking system for WordPress — schedule appointments, manage calendars, send reminders, take payments. Start booking today!
Calendar Archives Developer Profile
1 plugin · 100 total installs
How We Detect Calendar Archives
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/calendar-archives/css/calendar-archives.css/wp-content/plugins/calendar-archives/js/calendar-archives.js/wp-content/plugins/calendar-archives/js/calendar-archives.jscalendar-archives/css/calendar-archives.css?ver=calendar-archives/js/calendar-archives.js?ver=HTML / DOM Fingerprints
calendar-archives-wrapper<!-- Calendar Archives --><!-- Calendar Archives: end -->data-ca-box-dimensiondata-ca-day-background-colordata-ca-day-box-background-colordata-ca-first-day-of-weekdata-ca-hide-no-posts-monthsdata-ca-layout+4 moreCalendarArchives<div class="calendar-archives-wrapper"><div class="calendar-archives-month"><div class="calendar-archives-day"