Display Event Location for The Events Calendar Security & Risk Analysis

wordpress.org/plugins/display-event-locations-tec

This plugin works with The Events Calendar by Modern Tribe. It adds an event's location information to the tooltip on the monthly calendar view.

100 active installs v4.6.0 PHP 7.0.0+ WP 5.0.0+ Updated Nov 24, 2025
customizationeventsmodern-tribeoverridetemplate
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Display Event Location for The Events Calendar Safe to Use in 2026?

Generally Safe

Score 100/100

Display Event Location for The Events Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "display-event-locations-tec" v4.6.0 plugin exhibits a strong security posture based on the provided static analysis. There are no identified dangerous functions, external HTTP requests, file operations, or SQL queries that are not properly prepared. Furthermore, all identified output is correctly escaped, and there are no taint flows of any severity, indicating a clean codebase with respect to common vulnerability vectors. The plugin also has no known vulnerabilities in its history, suggesting a history of secure development practices.

However, a notable concern is the complete absence of nonce checks and the presence of only one capability check across all entry points. While the static analysis shows zero unprotected entry points, the lack of robust authentication and authorization mechanisms across potential interaction points is a weakness. This could become a concern if any future changes inadvertently expose new entry points or if the single capability check is insufficient for certain actions. The limited attack surface and lack of known vulnerabilities are significant strengths, but the minimal use of security checks warrants caution for future development.

In conclusion, the plugin demonstrates excellent code hygiene and a strong history of security. The absence of critical code-level risks is a significant positive. The primary area for improvement and potential future risk lies in strengthening the authentication and authorization checks around its interaction points. While currently presenting a low immediate risk, this could be a point of failure if the plugin's functionality expands or if the existing checks are misconfigured.

Key Concerns

  • Missing nonce checks
  • Limited capability checks across entry points
Vulnerabilities
None known

Display Event Location for The Events Calendar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Display Event Location for The Events Calendar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
21 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped21 total outputs
Attack Surface

Display Event Location for The Events Calendar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filtertribe_template_theme_path_listdisplay-event-locations-tec.php:63
actiontribe_template_after_include:events/v2/month/calendar-body/day/calendar-events/calendar-event/tooltip/titledisplay-event-locations-tec.php:70
filterplugin_row_metadisplay-event-locations-tec.php:152
actionadmin_menuincludes\settings-page\admin-menu.php:24
actionadmin_initincludes\settings-page\settings-register.php:50
Maintenance & Trust

Display Event Location for The Events Calendar Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 24, 2025
PHP min version7.0.0
Downloads7K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Display Event Location for The Events Calendar Developer Profile

Michael Weiner

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Display Event Location for The Events Calendar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/display-event-locations-tec/tribe-templates/month/tooltip-venue.php

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Display Event Location for The Events Calendar