
DWBooster Integration for Calculated Fields Form with Google Calendar Security & Risk Analysis
wordpress.org/plugins/dwbooster-cff-google-calendar-integrationEasily sync your "Calculated Fields Form" Date/Timeslots controls with Google Calendar to manage schedules and prevent overlapping events.
Is DWBooster Integration for Calculated Fields Form with Google Calendar Safe to Use in 2026?
Generally Safe
Score 100/100DWBooster Integration for Calculated Fields Form with Google Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "dwbooster-cff-google-calendar-integration" v1.0.0 exhibits a generally good security posture with strong adherence to best practices. The absence of critical or high severity taint flows, along with a high percentage of prepared SQL statements and properly escaped outputs, indicates a solid foundation. The plugin also demonstrates good defensive coding by implementing nonce checks and capability checks on its AJAX endpoints, and it has no recorded vulnerability history, suggesting a proactive approach to security or a lack of historical targeting.
However, there are a couple of specific areas for concern. The presence of two taint flows with unsanitized paths, even if not classified as critical or high severity in the static analysis, represents a potential risk. While the static analysis didn't flag them as critical, unsanitized paths can be a vector for various attacks if they interact with other parts of the system or user-controlled input in unexpected ways. The limited number of capability checks (only 1) is also a potential weakness, as it implies that not all AJAX handlers are adequately protected against unauthorized access, even though all are currently reported as having auth checks, this could be a false positive or a very minimal check.
In conclusion, the plugin is well-developed from a security perspective, with most potential vulnerabilities addressed through prepared statements, output escaping, and nonce/capability checks. The primary weaknesses lie in the two identified taint flows with unsanitized paths and the limited number of explicit capability checks, which warrant further investigation and potential remediation to ensure a robust security profile.
Key Concerns
- Two taint flows with unsanitized paths
- Limited capability checks on entry points
DWBooster Integration for Calculated Fields Form with Google Calendar Security Vulnerabilities
DWBooster Integration for Calculated Fields Form with Google Calendar Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
DWBooster Integration for Calculated Fields Form with Google Calendar Attack Surface
AJAX Handlers 5
WordPress Hooks 11
Maintenance & Trust
DWBooster Integration for Calculated Fields Form with Google Calendar Maintenance & Trust
Maintenance Signals
Community Trust
DWBooster Integration for Calculated Fields Form with Google Calendar Alternatives
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
ICS Calendar
ics-calendar
Add the calendar you already use to Any WordPress site! Google Calendar, Microsoft 365, iCloud and more… no API keys or complicated setup required.
Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar
booking-manager
Showing events listing from .ics feeds or sync bookings from different sources to your website
Events Calendar for Google
events-calendar-for-google
Events Calendar for Google implements google calender to your wordpress website using different style and layouts. Get connected to your audience usin …
Simple Google Calendar Outlook Events Widget
simple-google-icalendar-widget
Block widget that displays events from a public google calendar or iCal file.
DWBooster Integration for Calculated Fields Form with Google Calendar Developer Profile
1 plugin · 0 total installs
How We Detect DWBooster Integration for Calculated Fields Form with Google Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dwbooster-cff-google-calendar-integration/googlecalendar.addon/calendar-api.php/wp-content/plugins/dwbooster-cff-google-calendar-integration/assets/styles.css/wp-content/plugins/dwbooster-cff-google-calendar-integration/assets/script.js/wp-content/plugins/dwbooster-cff-google-calendar-integration/assets/script.jsdwbooster-cff-google-calendar-integration/assets/styles.css?ver=dwbooster-cff-google-calendar-integration/assets/script.js?ver=HTML / DOM Fingerprints
data-cff-google-calendar-configcff_google_calendar_admin_config/wp-json/cff-google-calendar-integration/v1/settings/wp-json/cff-google-calendar-integration/v1/calendars/wp-json/cff-google-calendar-integration/v1/events