DWBooster Integration for Calculated Fields Form with Google Calendar Security & Risk Analysis

wordpress.org/plugins/dwbooster-cff-google-calendar-integration

Easily sync your "Calculated Fields Form" Date/Timeslots controls with Google Calendar to manage schedules and prevent overlapping events.

0 active installs v1.0.0 PHP 7.0+ WP 6.0+ Updated Nov 28, 2025
calculated-fields-formcalendareventsgoogletimeslots
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is DWBooster Integration for Calculated Fields Form with Google Calendar Safe to Use in 2026?

Generally Safe

Score 100/100

DWBooster Integration for Calculated Fields Form with Google Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The plugin "dwbooster-cff-google-calendar-integration" v1.0.0 exhibits a generally good security posture with strong adherence to best practices. The absence of critical or high severity taint flows, along with a high percentage of prepared SQL statements and properly escaped outputs, indicates a solid foundation. The plugin also demonstrates good defensive coding by implementing nonce checks and capability checks on its AJAX endpoints, and it has no recorded vulnerability history, suggesting a proactive approach to security or a lack of historical targeting.

However, there are a couple of specific areas for concern. The presence of two taint flows with unsanitized paths, even if not classified as critical or high severity in the static analysis, represents a potential risk. While the static analysis didn't flag them as critical, unsanitized paths can be a vector for various attacks if they interact with other parts of the system or user-controlled input in unexpected ways. The limited number of capability checks (only 1) is also a potential weakness, as it implies that not all AJAX handlers are adequately protected against unauthorized access, even though all are currently reported as having auth checks, this could be a false positive or a very minimal check.

In conclusion, the plugin is well-developed from a security perspective, with most potential vulnerabilities addressed through prepared statements, output escaping, and nonce/capability checks. The primary weaknesses lie in the two identified taint flows with unsanitized paths and the limited number of explicit capability checks, which warrant further investigation and potential remediation to ensure a robust security profile.

Key Concerns

  • Two taint flows with unsanitized paths
  • Limited capability checks on entry points
Vulnerabilities
None known

DWBooster Integration for Calculated Fields Form with Google Calendar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

DWBooster Integration for Calculated Fields Form with Google Calendar Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
15 prepared
Unescaped Output
2
73 escaped
Nonce Checks
7
Capability Checks
1
File Operations
0
External Requests
8
Bundled Libraries
0

SQL Query Safety

83% prepared18 total queries

Output Escaping

97% escaped75 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
get_events (cff-google-calendar.php:749)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

DWBooster Integration for Calculated Fields Form with Google Calendar Attack Surface

Entry Points5
Unprotected0

AJAX Handlers 5

authwp_ajax_cff_google_calendar_get_eventscff-google-calendar.php:65
noprivwp_ajax_cff_google_calendar_get_eventscff-google-calendar.php:66
authwp_ajax_cff_google_calendar_validatecff-google-calendar.php:67
noprivwp_ajax_cff_google_calendar_validatecff-google-calendar.php:68
authwp_ajax_cff_google_calendar_get_calendars_listcff-google-calendar.php:77
WordPress Hooks 11
actionwpmu_new_blogcff-google-calendar.php:50
actioncpcff_form_settingscff-google-calendar.php:53
actionadmin_initcff-google-calendar.php:55
filtercpcff_the_formcff-google-calendar.php:64
actioncpcff_script_after_validationcff-google-calendar.php:71
actionadmin_enqueue_scriptscff-google-calendar.php:75
actionadmin_menucff-google-calendar.php:80
actioncpcff_delete_formcff-google-calendar.php:83
actioncpcff_clone_formcff-google-calendar.php:86
actioncpcff_export_addonscff-google-calendar.php:89
actioncpcff_import_addonscff-google-calendar.php:92
Maintenance & Trust

DWBooster Integration for Calculated Fields Form with Google Calendar Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 28, 2025
PHP min version7.0
Downloads156

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

DWBooster Integration for Calculated Fields Form with Google Calendar Developer Profile

CodePeople2

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DWBooster Integration for Calculated Fields Form with Google Calendar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dwbooster-cff-google-calendar-integration/googlecalendar.addon/calendar-api.php/wp-content/plugins/dwbooster-cff-google-calendar-integration/assets/styles.css/wp-content/plugins/dwbooster-cff-google-calendar-integration/assets/script.js
Script Paths
/wp-content/plugins/dwbooster-cff-google-calendar-integration/assets/script.js
Version Parameters
dwbooster-cff-google-calendar-integration/assets/styles.css?ver=dwbooster-cff-google-calendar-integration/assets/script.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-cff-google-calendar-config
JS Globals
cff_google_calendar_admin_config
REST Endpoints
/wp-json/cff-google-calendar-integration/v1/settings/wp-json/cff-google-calendar-integration/v1/calendars/wp-json/cff-google-calendar-integration/v1/events
FAQ

Frequently Asked Questions about DWBooster Integration for Calculated Fields Form with Google Calendar