Event Calendar by Timely Security & Risk Analysis

wordpress.org/plugins/event-calendar-timely

Attract, engage, and grow your audience with Timely’s free event calendar app. The calendar plugin for WordPress trusted by event managers worldwide.

300 active installs v1.0.1 PHP 7.3+ WP 5.0+ Updated Sep 3, 2025
calendar-widgeteventevent-calendarevent-calendar-plugin-for-wordpressevents-calendar
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Event Calendar by Timely Safe to Use in 2026?

Generally Safe

Score 100/100

Event Calendar by Timely has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The plugin "event-calendar-timely" v1.0.1 demonstrates a strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and the complete use of prepared statements for SQL queries are excellent indicators. Furthermore, all detected output is properly escaped, and the presence of a nonce check on one of its entry points is a positive sign of basic security practices. The plugin's vulnerability history is also clean, with no recorded CVEs, suggesting a history of secure development or diligent patching by the maintainers.

However, there are areas for improvement. The plugin has two AJAX handlers, and while the static analysis indicates zero are unprotected, this is a critical point to verify as it represents the primary attack surface. The lack of capability checks on these AJAX handlers, as indicated by the 0 count, is a significant concern. Even if an AJAX handler appears protected by a nonce, an attacker could potentially bypass this if the underlying functionality doesn't perform its own capability checks, allowing privileged actions to be performed by unauthenticated or low-privileged users. The single external HTTP request, while not inherently a vulnerability, warrants scrutiny for potential data leakage or further attack vectors.

In conclusion, the plugin exhibits many good security practices, particularly in its handling of SQL and output. The main weakness lies in the potential for privilege escalation through AJAX handlers that do not enforce capability checks. The clean vulnerability history is a positive indicator, but the identified gaps in capability checks on entry points represent a tangible risk that should be addressed.

Key Concerns

  • AJAX handlers without capability checks
  • External HTTP request found
Vulnerabilities
None known

Event Calendar by Timely Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Event Calendar by Timely Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
26 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped26 total outputs
Attack Surface

Event Calendar by Timely Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

noprivwp_ajax_timely_auth_tokensrc\Timely_Event_Calendar.php:33
authwp_ajax_timely_auth_tokensrc\Timely_Event_Calendar.php:34
WordPress Hooks 1
actionadmin_menusrc\Timely_Event_Calendar.php:32
Maintenance & Trust

Event Calendar by Timely Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 3, 2025
PHP min version7.3
Downloads2K

Community Trust

Rating26/100
Number of ratings3
Active installs300
Developer Profile

Event Calendar by Timely Developer Profile

Timely Calendar Team

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Event Calendar by Timely

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/event-calendar-timely/dist/styles/embed-calendar.css/wp-content/plugins/event-calendar-timely/dist/embed-calendar.js
Script Paths
/wp-content/plugins/event-calendar-timely/dist/embed-calendar.js
Version Parameters
event-calendar-timelytimely-embed-calendar-styletimely-embed-calendar-script

HTML / DOM Fingerprints

Data Attributes
data-srcdata-max-height
JS Globals
TIMELY_PATHTIMELY_PLUGIN_VERSION
Shortcode Output
<div id="timely-embed-calendar-placeholder"
FAQ

Frequently Asked Questions about Event Calendar by Timely