
Date Price Calendar for WooCommerce Security & Risk Analysis
wordpress.org/plugins/date-price-calendarIt displays a jQuery popup calendar as product option on the front-end product page.
Is Date Price Calendar for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Date Price Calendar for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "date-price-calendar" plugin version 1.0.0 presents a mixed security posture. On the positive side, it boasts zero known CVEs and no direct attack surface through shortcodes, AJAX, or REST API routes without authentication. The absence of file operations and external HTTP requests further reduces potential attack vectors. However, significant concerns arise from the code analysis. A low percentage of SQL queries are properly prepared, indicating a potential for SQL injection vulnerabilities. Furthermore, the output escaping is alarmingly low, with only 18% of outputs properly escaped, raising risks of Cross-Site Scripting (XSS) attacks. The taint analysis, while limited, shows flows with unsanitized paths, which, coupled with the low output escaping, could be exploited if a path is ever introduced through other means.
The vulnerability history is positive, with no recorded CVEs. This could indicate a well-developed and secure plugin, or it could be due to its limited adoption or a lack of comprehensive security audits. The strengths lie in its lack of obvious entry points and a clean vulnerability history. The weaknesses are concentrated in the potential for SQL injection due to unprepared queries and XSS due to insufficient output escaping. While the current attack surface appears minimal, the identified code-level weaknesses represent significant risks if any of these code paths become exposed or if malicious input is processed without proper sanitization and escaping.
Key Concerns
- Low percentage of prepared SQL statements
- Low percentage of properly escaped output
- Taint analysis shows unsanitized paths
Date Price Calendar for WooCommerce Security Vulnerabilities
Date Price Calendar for WooCommerce Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Date Price Calendar for WooCommerce Attack Surface
WordPress Hooks 13
Maintenance & Trust
Date Price Calendar for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Date Price Calendar for WooCommerce Alternatives
No alternatives data available yet.
Date Price Calendar for WooCommerce Developer Profile
14 plugins · 6K total installs
How We Detect Date Price Calendar for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/date-price-calendar/view/adminhtml/web/product/edit/main.js/wp-content/plugins/date-price-calendar/view/adminhtml/web/product/edit/main.css/wp-content/plugins/date-price-calendar/view/frontend/web/main.js/wp-content/plugins/date-price-calendar/view/frontend/web/main.css/wp-content/plugins/date-price-calendar/view/frontend/web/odp-ui-datepicker.css/wp-content/plugins/date-price-calendar/view/adminhtml/web/product/edit/main.js/wp-content/plugins/date-price-calendar/view/frontend/web/main.jsdate-price-calendar/view/adminhtml/web/product/edit/main.js?ver=date-price-calendar/view/adminhtml/web/product/edit/main.css?ver=date-price-calendar/view/frontend/web/main.js?ver=date-price-calendar/view/frontend/web/main.css?ver=date-price-calendar/view/frontend/web/odp-ui-datepicker.css?ver=HTML / DOM Fingerprints
odp_product_dataodp-calendar-wrapperdata-product_iddata-odp_optionsodp_product_view_params