
CPT Calender Widget for WordPress Security & Risk Analysis
wordpress.org/plugins/cpt-calender-widgetCreate Custom Post and and select CPT from dropdown.
Is CPT Calender Widget for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100CPT Calender Widget for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of cpt-calender-widget v1.0.0 reveals a generally good security posture regarding attack surface. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, meaning there are no direct entry points for attackers to exploit. This lack of exposed functionality is a significant strength. However, the code does contain one instance of the `create_function` which is considered a dangerous function in PHP and can be a vector for code injection if user input is not strictly controlled. Additionally, only 17% of SQL queries utilize prepared statements, leaving a substantial portion vulnerable to SQL injection. The 50% rate of proper output escaping is also a concern, indicating potential for cross-site scripting (XSS) vulnerabilities. The absence of any recorded vulnerabilities in its history is a positive indicator, suggesting the developers have maintained security over time. Despite the clean vulnerability history, the presence of dangerous functions and insecure SQL practices warrants caution. Overall, while the plugin has a minimal attack surface, the identified code-level issues represent potential security risks that need to be addressed.
Key Concerns
- Dangerous function used (create_function)
- High percentage of SQL queries not using prepared statements
- Output escaping is not consistently applied
- Missing nonce checks
- Missing capability checks
CPT Calender Widget for WordPress Security Vulnerabilities
CPT Calender Widget for WordPress Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
CPT Calender Widget for WordPress Attack Surface
WordPress Hooks 4
Maintenance & Trust
CPT Calender Widget for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
CPT Calender Widget for WordPress Alternatives
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
Event Calendar by Timely
event-calendar-timely
Attract, engage, and grow your audience with Timely’s free event calendar app. The calendar plugin for WordPress trusted by event managers worldwide.
The Events Calendar
the-events-calendar
The Events Calendar: #1 calendar plugin for WordPress. Create/manage events (virtual too!) on your site with the free plugin.
LatePoint – Calendar Booking Plugin for Appointments and Events
latepoint
Optimize your appointment scheduling with our plugin. Sync calendars, automate reminders, and keep your bookings organized.
Online Scheduling and Appointment Booking System – Bookly
bookly-responsive-appointment-booking-tool
Appointment booking system for WordPress — schedule appointments, manage calendars, send reminders, take payments. Start booking today!
CPT Calender Widget for WordPress Developer Profile
2 plugins · 110 total installs
How We Detect CPT Calender Widget for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
widget_calendarcalendar_wrapid="calendar_wrap"