
Event Calendar – Calendar Security & Risk Analysis
wordpress.org/plugins/calendar-eventEvent Calendar plugin created for showing your events. Event Calendar is the best if you want to be original on your website.
Is Event Calendar – Calendar Safe to Use in 2026?
Generally Safe
Score 99/100Event Calendar – Calendar has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'calendar-event' plugin version 1.6.0 demonstrates strong adherence to many security best practices, with a low immediate risk based on the provided static analysis. The plugin exhibits excellent practices regarding SQL query sanitization and output escaping, with 99% and 98% respectively utilizing prepared statements and proper escaping. The attack surface, while present with 8 AJAX handlers and 1 shortcode, appears to be protected, as there are no reported unprotected entry points. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests in the code signals a generally secure coding approach. Taint analysis also indicates no critical or high severity flows with unsanitized paths.
However, the plugin's vulnerability history presents a notable concern. It has a total of 2 known CVEs, both classified as medium severity and related to Cross-site Scripting and Missing Authorization. While there are currently no unpatched vulnerabilities, the historical pattern suggests past weaknesses in input validation and authorization mechanisms. The presence of these past vulnerabilities, even if patched, warrants vigilance. The bundled TinyMCE v1.0 library is also a potential area of concern if it is an outdated version that could harbor known vulnerabilities.
In conclusion, the 'calendar-event' plugin version 1.6.0 shows a good security posture in its current code with robust sanitization and escaping. The primary weakness lies in its past vulnerability history, indicating a need for continued monitoring and assurance that past issues have been thoroughly addressed. The bundled library also requires attention.
Key Concerns
- Past medium severity vulnerabilities (XSS, Missing Auth)
- Bundled outdated library (TinyMCE v1.0)
Event Calendar – Calendar Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Event Calendar <= 1.4.6 - Reflected Cross-Site Scripting
Event Calendar <= 1.4.6 - Missing Authorization to Event Modification
Event Calendar – Calendar Release Timeline
Event Calendar – Calendar Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Event Calendar – Calendar Attack Surface
AJAX Handlers 8
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Event Calendar – Calendar Maintenance & Trust
Maintenance Signals
Community Trust
Event Calendar – Calendar Alternatives
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
Events Widgets For Elementor And The Events Calendar
events-widgets-for-elementor-and-the-events-calendar
The Events Calendar Elementor widgets help you manage and display an upcoming events list with date, time, venue and event ticket booking details.
Sugar Calendar – Events Calendar, Event Tickets, and Events Management Platform
sugar-calendar-lite
Easily manage events and sell tickets on your WordPress site. Sugar Calendar is easy-to-use, reliable, and exceptionally powerful. See for yourself.
Events Shortcodes For The Events Calendar
template-events-calendar
Add The Events Calendar shortcode or Gutenberg block to show upcoming events list with event details on any WordPress page using smart event filters.
WP FullCalendar
wp-fullcalendar
Uses the FullCalendar library to create a stunning calendar view of events, posts and other custom post types
Event Calendar – Calendar Developer Profile
4 plugins · 17K total installs
How We Detect Event Calendar – Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/calendar-event/CSS/Total-Soft-Calendar-Widget.css/wp-content/plugins/calendar-event/CSS/totalsoft.css/wp-content/plugins/calendar-event/JS/Total-Soft-Calendar-Widget.js/wp-content/plugins/calendar-event/JS/Total-Soft-Calendar-Admin.js/wp-content/plugins/calendar-event/JS/alpha-color-picker.js/wp-content/plugins/calendar-event/CSS/alpha-color-picker.css/wp-content/plugins/calendar-event/JS/Total-Soft-Calendar-Widget.js/wp-content/plugins/calendar-event/JS/Total-Soft-Calendar-Admin.js/wp-content/plugins/calendar-event/JS/alpha-color-picker.jscalendar-event/CSS/Total-Soft-Calendar-Widget.css?ver=calendar-event/CSS/totalsoft.css?ver=calendar-event/JS/Total-Soft-Calendar-Widget.js?ver=calendar-event/JS/Total-Soft-Calendar-Admin.js?ver=calendar-event/JS/alpha-color-picker.js?ver=calendar-event/CSS/alpha-color-picker.css?ver=HTML / DOM Fingerprints
totalsoft_cal_widgettotalsoft_cal_admin<!-- CALENDAR EVENT MANAGER --><!-- CALENDAR EVENTS -->data-tsc-noncedata-ts-calendar-noncets_calendar_object[Total_Soft_Cal id=