cityevents Security & Risk Analysis

wordpress.org/plugins/cityevents

Display cultural events from iltaccodibacco.it on your WordPress site, filtered by city and including events within a 30 km radius.

0 active installs v0.1.12 PHP 7.4+ WP 5.8+ Updated Sep 25, 2025
agendaconcertscultureeventsitaly
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is cityevents Safe to Use in 2026?

Generally Safe

Score 100/100

cityevents has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The "cityevents" plugin, in version 0.1.14, exhibits a generally positive security posture based on the provided static analysis. The plugin has a minimal attack surface with only one shortcode and no unprotected entry points identified. The code also demonstrates good practices by using prepared statements for all SQL queries and properly escaping the vast majority (95%) of its outputs. There are no critical or high severity taint flows detected, indicating a lack of easily exploitable vulnerabilities through unsanitized input. Furthermore, the plugin has no known historical vulnerabilities, suggesting a history of stable and secure development.

However, there are a few areas for improvement. The absence of nonce checks on the identified entry point is a concern, as it leaves the shortcode potentially vulnerable to Cross-Site Request Forgery (CSRF) attacks if it performs any sensitive actions. While the capability check is present, its effectiveness is diminished without a nonce to prevent unauthorized execution of the shortcode's functionality. The single external HTTP request, while not inherently a vulnerability, is an area that warrants careful scrutiny to ensure it is handled securely and does not expose the site to risks from compromised external resources.

In conclusion, "cityevents" v0.1.14 is a relatively secure plugin with a strong foundation in secure coding practices. The lack of known vulnerabilities and good handling of SQL and output escaping are significant strengths. The primary weakness lies in the missing nonce check, which should be addressed to mitigate potential CSRF risks.

Key Concerns

  • Missing nonce check on entry point
Vulnerabilities
None known

cityevents Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

cityevents Release Timeline

v0.1.12Current
Code Analysis
Analyzed Apr 16, 2026

cityevents Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
101 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

95% escaped106 total outputs
Attack Surface

cityevents Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[cityevents] cityevents-plugin.php:24
WordPress Hooks 3
actionwidgets_initcityevents-plugin.php:23
actionadmin_menucityevents-plugin.php:38
actionadmin_initcityevents-plugin.php:39
Maintenance & Trust

cityevents Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 25, 2025
PHP min version7.4
Downloads990

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

cityevents Developer Profile

Cognita

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect cityevents

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cityevents/assets/css/cityevents.css
Version Parameters
cityevents/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
cityevents-widgetcityevents-widget-title
HTML Comments
<!-- Default options are used for widgets and shortcodes (can be overridden) --><!-- CityEvents options -->
Data Attributes
data-cityevents-shortcode
Shortcode Output
<div class="cityevents-widget"><h3 class="cityevents-widget-title">
FAQ

Frequently Asked Questions about cityevents