
Display Event Location for The Events Calendar Security & Risk Analysis
wordpress.org/plugins/display-event-locations-tecThis plugin works with The Events Calendar by Modern Tribe. It adds an event's location information to the tooltip on the monthly calendar view.
Is Display Event Location for The Events Calendar Safe to Use in 2026?
Generally Safe
Score 100/100Display Event Location for The Events Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "display-event-locations-tec" v4.6.0 plugin exhibits a strong security posture based on the provided static analysis. There are no identified dangerous functions, external HTTP requests, file operations, or SQL queries that are not properly prepared. Furthermore, all identified output is correctly escaped, and there are no taint flows of any severity, indicating a clean codebase with respect to common vulnerability vectors. The plugin also has no known vulnerabilities in its history, suggesting a history of secure development practices.
However, a notable concern is the complete absence of nonce checks and the presence of only one capability check across all entry points. While the static analysis shows zero unprotected entry points, the lack of robust authentication and authorization mechanisms across potential interaction points is a weakness. This could become a concern if any future changes inadvertently expose new entry points or if the single capability check is insufficient for certain actions. The limited attack surface and lack of known vulnerabilities are significant strengths, but the minimal use of security checks warrants caution for future development.
In conclusion, the plugin demonstrates excellent code hygiene and a strong history of security. The absence of critical code-level risks is a significant positive. The primary area for improvement and potential future risk lies in strengthening the authentication and authorization checks around its interaction points. While currently presenting a low immediate risk, this could be a point of failure if the plugin's functionality expands or if the existing checks are misconfigured.
Key Concerns
- Missing nonce checks
- Limited capability checks across entry points
Display Event Location for The Events Calendar Security Vulnerabilities
Display Event Location for The Events Calendar Code Analysis
Output Escaping
Display Event Location for The Events Calendar Attack Surface
WordPress Hooks 5
Maintenance & Trust
Display Event Location for The Events Calendar Maintenance & Trust
Maintenance Signals
Community Trust
Display Event Location for The Events Calendar Alternatives
Event Single Page Builder For The Events Calendar
event-page-templates-addon-for-the-events-calendar
The Events Calendar addon to create custom single event page templates and replace the default event single page layout with your own branded design.
Duplicate TEC Event
duplicate-tec-event
Adds the ability to duplicate an event created by Modern Tribe's The Event Calendar plugin.
Musician's Pack for Elementor – Music Website Widgets & Templates
music-pack-for-elementor
Create stunning music websites with Musician's Pack for Elementor! Powerful widgets & ready-made templates for musicians, bands, DJs, and producers.
The Events Calendar Outlook Import Fix
the-events-calendar-outlook-import-fix
Fix import of calendar events from The Events Calendar to Outlook.
The Events Calendar User CSS
the-events-calendar-user-css
A plugin to correctly load users custom CSS overrides for The Events Calendar PRO.
Display Event Location for The Events Calendar Developer Profile
1 plugin · 100 total installs
How We Detect Display Event Location for The Events Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/display-event-locations-tec/tribe-templates/month/tooltip-venue.php