
CitySpark Events and Embeds Security & Risk Analysis
wordpress.org/plugins/cityspark-events-and-embeds© 2025 CitySpark. All Rights Reserved
Is CitySpark Events and Embeds Safe to Use in 2026?
Generally Safe
Score 100/100CitySpark Events and Embeds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "cityspark-events-and-embeds" plugin v0.1.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any recorded vulnerabilities in its history is a positive indicator. Furthermore, the code demonstrates good practices with 100% of SQL queries using prepared statements and all output escaping being properly handled. The lack of file operations and external HTTP requests also reduces potential attack vectors.
However, a significant concern arises from the taint analysis revealing two flows with unsanitized paths. While the severity is not explicitly high or critical, unsanitized paths can still lead to various vulnerabilities if they are not properly handled upstream or within the application's broader context. The lack of nonce checks and capability checks on the identified entry points (though there are none reported) is a potential area of future risk if the plugin evolves to include them without proper security considerations.
In conclusion, the plugin's current state appears robust due to diligent coding practices and a clean vulnerability history. The primary area for improvement lies in thoroughly addressing the identified unsanitized path flows to eliminate any potential for exploitation, even if they are not currently classified as critical.
Key Concerns
- Unsanitized paths in taint analysis
- No nonce checks on entry points
- No capability checks on entry points
CitySpark Events and Embeds Security Vulnerabilities
CitySpark Events and Embeds Release Timeline
CitySpark Events and Embeds Code Analysis
Output Escaping
Data Flow Analysis
CitySpark Events and Embeds Attack Surface
WordPress Hooks 20
Maintenance & Trust
CitySpark Events and Embeds Maintenance & Trust
Maintenance Signals
Community Trust
CitySpark Events and Embeds Alternatives
Spiffy Calendar
spiffy-calendar
Manage and display your events in a responsive calendar with multiple views, widgets and shortcodes. Color-coded categories and recurrence support.
Events Block For The Events Calendar
events-block-for-the-events-calendar
The Events Block for The Events Calendar lets you showcase your events from The Events Calendar right within the Gutenberg pages.
Simple Google Calendar Outlook Events Widget
simple-google-icalendar-widget
Block widget that displays events from a public google calendar or iCal file.
Slider Addons for The Events Calendar
tecslider
Slider Blocks to showcase your events.
Eventim US Event Listings
eventim-us-event-listings
Display and manage event listings with advanced customization options, powered by Eventim US.
CitySpark Events and Embeds Developer Profile
1 plugin · 60 total installs
How We Detect CitySpark Events and Embeds
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cityspark-events-and-embeds/build/portal_block/index.js/wp-content/plugins/cityspark-events-and-embeds/build/listpage_block/index.js/wp-content/plugins/cityspark-events-and-embeds/build/widget-block/index.jshttps://cdn.cityspark.com/wid/get.jscityspark-events-and-embeds/build/portal_block/index.asset.phpcityspark-events-and-embeds/build/listpage_block/index.asset.phpcityspark-events-and-embeds/build/widget-block/index.asset.phpHTML / DOM Fingerprints
citysparkData