
CiviEvent Widget Security & Risk Analysis
wordpress.org/plugins/civievent-widgetDisplay widgets for CiviCRM events: the next public event or a whole list. Embed widgets as shortcodes, too!
Is CiviEvent Widget Safe to Use in 2026?
Generally Safe
Score 85/100CiviEvent Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "civievent-widget" v3.2 plugin demonstrates a generally good security posture, with no recorded vulnerabilities or critical findings in taint analysis. The complete absence of dangerous functions, file operations, and external HTTP requests is commendable. All SQL queries are properly prepared, which mitigates the risk of SQL injection. However, there are significant concerns regarding output escaping, with only 23% of outputs being properly escaped. This leaves the plugin vulnerable to cross-site scripting (XSS) attacks, where malicious scripts could be injected and executed in users' browsers. The lack of nonce checks and capability checks on the identified entry points (shortcodes) is also a weakness, although the attack surface is small. The absence of vulnerability history suggests the plugin may be well-maintained or has not been a target of significant exploitation, but this does not negate the risks identified in the static analysis.
Key Concerns
- Low percentage of properly escaped output
- Missing nonce checks on entry points
- Missing capability checks on entry points
CiviEvent Widget Security Vulnerabilities
CiviEvent Widget Code Analysis
Output Escaping
CiviEvent Widget Attack Surface
Shortcodes 2
WordPress Hooks 1
Maintenance & Trust
CiviEvent Widget Maintenance & Trust
Maintenance Signals
Community Trust
CiviEvent Widget Alternatives
NeonCRM Events Widget
neoncrm-events-widget
Displays a feed of upcoming events retrieved from NeonCRM.
CiviCRM Event List
orcas-civicrm-event-list
Show all your Events managed with CiviCRM in your frontend.
Nonprofit Manager
nonprofit-manager
Comprehensive nonprofit management solution for memberships, donations, newsletters, and events.
The Events Calendar
the-events-calendar
The Events Calendar: #1 calendar plugin for WordPress. Create/manage events (virtual too!) on your site with the free plugin.
LatePoint – Calendar Booking Plugin for Appointments and Events
latepoint
Optimize your appointment scheduling with our plugin. Sync calendars, automate reminders, and keep your bookings organized.
CiviEvent Widget Developer Profile
1 plugin · 200 total installs
How We Detect CiviEvent Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/civievent-widget/civievent-widget.csscivievent-widget.css?ver=HTML / DOM Fingerprints
civievent-widgetcivievent-widget-listCopyright 2013-2015 AGH Strategies, LLCThis program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU Affero General Public License+17 moredata-widget-titledata-widget-summarydata-widget-limitdata-widget-alllinkdata-widget-wthemedata-widget-divider+7 more<div class="civievent-widget"><div class="civievent-widget-list">