CitySpark Events and Embeds Security & Risk Analysis

wordpress.org/plugins/cityspark-events-and-embeds

© 2025 CitySpark. All Rights Reserved

60 active installs v0.1.2 PHP 7.2+ WP 5.2+ Updated Jun 17, 2025
blockbusiness-listingscalendareventlistings
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is CitySpark Events and Embeds Safe to Use in 2026?

Generally Safe

Score 100/100

CitySpark Events and Embeds has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "cityspark-events-and-embeds" plugin v0.1.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any recorded vulnerabilities in its history is a positive indicator. Furthermore, the code demonstrates good practices with 100% of SQL queries using prepared statements and all output escaping being properly handled. The lack of file operations and external HTTP requests also reduces potential attack vectors.

However, a significant concern arises from the taint analysis revealing two flows with unsanitized paths. While the severity is not explicitly high or critical, unsanitized paths can still lead to various vulnerabilities if they are not properly handled upstream or within the application's broader context. The lack of nonce checks and capability checks on the identified entry points (though there are none reported) is a potential area of future risk if the plugin evolves to include them without proper security considerations.

In conclusion, the plugin's current state appears robust due to diligent coding practices and a clean vulnerability history. The primary area for improvement lies in thoroughly addressing the identified unsanitized path flows to eliminate any potential for exploitation, even if they are not currently classified as critical.

Key Concerns

  • Unsanitized paths in taint analysis
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

CitySpark Events and Embeds Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

CitySpark Events and Embeds Release Timeline

v0.1.2Current
v0.1.1
v0.1.0
Code Analysis
Analyzed Mar 16, 2026

CitySpark Events and Embeds Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
17 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped17 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
ctsp_add_og_meta_tags (includes\canonical.php:258)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

CitySpark Events and Embeds Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actioninitcityspark-events-and-embeds.php:34
actioninitcityspark-events-and-embeds.php:97
actioninitcityspark-events-and-embeds.php:98
actioninitcityspark-events-and-embeds.php:99
actionwp_footercityspark-events-and-embeds.php:113
filterwpseo_canonicalincludes\canonical.php:242
filterwpseo_titleincludes\canonical.php:243
filterwpseo_opengraph_titleincludes\canonical.php:244
filterwpseo_opengraph_descincludes\canonical.php:245
filterwpseo_opengraph_urlincludes\canonical.php:246
filterwpseo_opengraph_imageincludes\canonical.php:247
filterwpseo_opengraph_image_widthincludes\canonical.php:248
filterwpseo_opengraph_image_heightincludes\canonical.php:249
filterwpseo_opengraph_image_typeincludes\canonical.php:250
actionwpseo_headincludes\canonical.php:251
filterget_canonical_urlincludes\canonical.php:254
filterpre_get_document_titleincludes\canonical.php:255
actionwp_headincludes\canonical.php:281
actionadmin_menuincludes\settings.php:21
filterrewrite_rules_arrayincludes\settings.php:43
Maintenance & Trust

CitySpark Events and Embeds Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 17, 2025
PHP min version7.2
Downloads551

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

CitySpark Events and Embeds Developer Profile

Ty Davis

1 plugin · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CitySpark Events and Embeds

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cityspark-events-and-embeds/build/portal_block/index.js/wp-content/plugins/cityspark-events-and-embeds/build/listpage_block/index.js/wp-content/plugins/cityspark-events-and-embeds/build/widget-block/index.js
Script Paths
https://cdn.cityspark.com/wid/get.js
Version Parameters
cityspark-events-and-embeds/build/portal_block/index.asset.phpcityspark-events-and-embeds/build/listpage_block/index.asset.phpcityspark-events-and-embeds/build/widget-block/index.asset.php

HTML / DOM Fingerprints

JS Globals
citysparkData
FAQ

Frequently Asked Questions about CitySpark Events and Embeds