Date Price Calendar for WooCommerce Security & Risk Analysis

wordpress.org/plugins/date-price-calendar

It displays a jQuery popup calendar as product option on the front-end product page.

70 active installs v1.0.0 PHP + WP 4.7+ Updated Nov 9, 2025
available-date-rangescalendar-product-optiondate-product-optionprice-per-date
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Date Price Calendar for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Date Price Calendar for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "date-price-calendar" plugin version 1.0.0 presents a mixed security posture. On the positive side, it boasts zero known CVEs and no direct attack surface through shortcodes, AJAX, or REST API routes without authentication. The absence of file operations and external HTTP requests further reduces potential attack vectors. However, significant concerns arise from the code analysis. A low percentage of SQL queries are properly prepared, indicating a potential for SQL injection vulnerabilities. Furthermore, the output escaping is alarmingly low, with only 18% of outputs properly escaped, raising risks of Cross-Site Scripting (XSS) attacks. The taint analysis, while limited, shows flows with unsanitized paths, which, coupled with the low output escaping, could be exploited if a path is ever introduced through other means.

The vulnerability history is positive, with no recorded CVEs. This could indicate a well-developed and secure plugin, or it could be due to its limited adoption or a lack of comprehensive security audits. The strengths lie in its lack of obvious entry points and a clean vulnerability history. The weaknesses are concentrated in the potential for SQL injection due to unprepared queries and XSS due to insufficient output escaping. While the current attack surface appears minimal, the identified code-level weaknesses represent significant risks if any of these code paths become exposed or if malicious input is processed without proper sanitization and escaping.

Key Concerns

  • Low percentage of prepared SQL statements
  • Low percentage of properly escaped output
  • Taint analysis shows unsanitized paths
Vulnerabilities
None known

Date Price Calendar for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Date Price Calendar for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
10
4 prepared
Unescaped Output
54
12 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

29% prepared14 total queries

Output Escaping

18% escaped66 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
execute (Controller\Adminhtml\Odp\Settings.php:16)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Date Price Calendar for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
actionadmin_enqueue_scriptsController\Adminhtml\Product.php:9
filterwoocommerce_product_data_tabsController\Adminhtml\Product.php:11
actionwoocommerce_product_data_panelsController\Adminhtml\Product.php:12
actionwp_enqueue_scriptsController\Product.php:8
actionwoocommerce_before_add_to_cart_buttonController\Product.php:9
actionadmin_menudate-price-calendar.php:62
actioninitdate-price-calendar.php:78
actionbefore_woocommerce_initdate-price-calendar.php:129
actionwoocommerce_add_to_cart_validationModel\Observer.php:27
actionwoocommerce_add_cart_item_dataModel\Observer.php:28
actionwoocommerce_before_calculate_totalsModel\Observer.php:29
actionwoocommerce_process_product_metaModel\Observer.php:30
actiondelete_postModel\Observer.php:31
Maintenance & Trust

Date Price Calendar for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 9, 2025
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs70
Alternatives

Date Price Calendar for WooCommerce Alternatives

No alternatives data available yet.

Developer Profile

Date Price Calendar for WooCommerce Developer Profile

Pektsekye

14 plugins · 6K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
8 days
View full developer profile
Detection Fingerprints

How We Detect Date Price Calendar for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/date-price-calendar/view/adminhtml/web/product/edit/main.js/wp-content/plugins/date-price-calendar/view/adminhtml/web/product/edit/main.css/wp-content/plugins/date-price-calendar/view/frontend/web/main.js/wp-content/plugins/date-price-calendar/view/frontend/web/main.css/wp-content/plugins/date-price-calendar/view/frontend/web/odp-ui-datepicker.css
Script Paths
/wp-content/plugins/date-price-calendar/view/adminhtml/web/product/edit/main.js/wp-content/plugins/date-price-calendar/view/frontend/web/main.js
Version Parameters
date-price-calendar/view/adminhtml/web/product/edit/main.js?ver=date-price-calendar/view/adminhtml/web/product/edit/main.css?ver=date-price-calendar/view/frontend/web/main.js?ver=date-price-calendar/view/frontend/web/main.css?ver=date-price-calendar/view/frontend/web/odp-ui-datepicker.css?ver=

HTML / DOM Fingerprints

CSS Classes
odp_product_dataodp-calendar-wrapper
Data Attributes
data-product_iddata-odp_options
JS Globals
odp_product_view_params
FAQ

Frequently Asked Questions about Date Price Calendar for WooCommerce