
cityevents Security & Risk Analysis
wordpress.org/plugins/cityeventsDisplay cultural events from iltaccodibacco.it on your WordPress site, filtered by city and including events within a 30 km radius.
Is cityevents Safe to Use in 2026?
Generally Safe
Score 100/100cityevents has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cityevents" plugin, in version 0.1.14, exhibits a generally positive security posture based on the provided static analysis. The plugin has a minimal attack surface with only one shortcode and no unprotected entry points identified. The code also demonstrates good practices by using prepared statements for all SQL queries and properly escaping the vast majority (95%) of its outputs. There are no critical or high severity taint flows detected, indicating a lack of easily exploitable vulnerabilities through unsanitized input. Furthermore, the plugin has no known historical vulnerabilities, suggesting a history of stable and secure development.
However, there are a few areas for improvement. The absence of nonce checks on the identified entry point is a concern, as it leaves the shortcode potentially vulnerable to Cross-Site Request Forgery (CSRF) attacks if it performs any sensitive actions. While the capability check is present, its effectiveness is diminished without a nonce to prevent unauthorized execution of the shortcode's functionality. The single external HTTP request, while not inherently a vulnerability, is an area that warrants careful scrutiny to ensure it is handled securely and does not expose the site to risks from compromised external resources.
In conclusion, "cityevents" v0.1.14 is a relatively secure plugin with a strong foundation in secure coding practices. The lack of known vulnerabilities and good handling of SQL and output escaping are significant strengths. The primary weakness lies in the missing nonce check, which should be addressed to mitigate potential CSRF risks.
Key Concerns
- Missing nonce check on entry point
cityevents Security Vulnerabilities
cityevents Release Timeline
cityevents Code Analysis
Output Escaping
cityevents Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
cityevents Maintenance & Trust
Maintenance Signals
Community Trust
cityevents Alternatives
Bandsintown Events
bandsintown
Bandsintown's Events plugin for displaying your upcoming events.
Songkick Concerts and Festivals
songkick-concerts-and-festivals
This plugin lets you display events for a Songkick user, artist, venue, or metro area on your WordPress blog, as a widget or shortcode.
Events as Posts
events-as-posts
A simple plugin that allows you to post events on your site.
OpenAgenda
openagenda
Display calendars from https://openagenda.com on your site.
Pronamic Events
pronamic-events
Pronamic Events is a basic plugin to add some Events functionality.
cityevents Developer Profile
1 plugin · 0 total installs
How We Detect cityevents
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cityevents/assets/css/cityevents.csscityevents/style.css?ver=HTML / DOM Fingerprints
cityevents-widgetcityevents-widget-title<!-- Default options are used for widgets and shortcodes (can be overridden) --><!-- CityEvents options -->data-cityevents-shortcode<div class="cityevents-widget"><h3 class="cityevents-widget-title">