
Event Calendar by Timely Security & Risk Analysis
wordpress.org/plugins/event-calendar-timelyAttract, engage, and grow your audience with Timely’s free event calendar app. The calendar plugin for WordPress trusted by event managers worldwide.
Is Event Calendar by Timely Safe to Use in 2026?
Generally Safe
Score 100/100Event Calendar by Timely has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "event-calendar-timely" v1.0.1 demonstrates a strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and the complete use of prepared statements for SQL queries are excellent indicators. Furthermore, all detected output is properly escaped, and the presence of a nonce check on one of its entry points is a positive sign of basic security practices. The plugin's vulnerability history is also clean, with no recorded CVEs, suggesting a history of secure development or diligent patching by the maintainers.
However, there are areas for improvement. The plugin has two AJAX handlers, and while the static analysis indicates zero are unprotected, this is a critical point to verify as it represents the primary attack surface. The lack of capability checks on these AJAX handlers, as indicated by the 0 count, is a significant concern. Even if an AJAX handler appears protected by a nonce, an attacker could potentially bypass this if the underlying functionality doesn't perform its own capability checks, allowing privileged actions to be performed by unauthenticated or low-privileged users. The single external HTTP request, while not inherently a vulnerability, warrants scrutiny for potential data leakage or further attack vectors.
In conclusion, the plugin exhibits many good security practices, particularly in its handling of SQL and output. The main weakness lies in the potential for privilege escalation through AJAX handlers that do not enforce capability checks. The clean vulnerability history is a positive indicator, but the identified gaps in capability checks on entry points represent a tangible risk that should be addressed.
Key Concerns
- AJAX handlers without capability checks
- External HTTP request found
Event Calendar by Timely Security Vulnerabilities
Event Calendar by Timely Code Analysis
Output Escaping
Event Calendar by Timely Attack Surface
AJAX Handlers 2
WordPress Hooks 1
Maintenance & Trust
Event Calendar by Timely Maintenance & Trust
Maintenance Signals
Community Trust
Event Calendar by Timely Alternatives
Events Widgets For Elementor And The Events Calendar
events-widgets-for-elementor-and-the-events-calendar
The Events Calendar Elementor widgets help you manage and display an upcoming events list with date, time, venue and event ticket booking details.
Events Shortcodes For The Events Calendar
template-events-calendar
Add The Events Calendar shortcode or Gutenberg block to show upcoming events list with event details on any WordPress page using smart event filters.
WP FullCalendar
wp-fullcalendar
Uses the FullCalendar library to create a stunning calendar view of events, posts and other custom post types
Event Single Page Builder For The Events Calendar
event-page-templates-addon-for-the-events-calendar
The Events Calendar addon to create custom single event page templates and replace the default event single page layout with your own branded design.
Event Countdown for The Events Calendar
countdown-for-the-events-calendar
Event countdown timer addon for The Events Calendar plugin to display upcoming event countdowns anywhere using a simple shortcode.
Event Calendar by Timely Developer Profile
1 plugin · 300 total installs
How We Detect Event Calendar by Timely
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/event-calendar-timely/dist/styles/embed-calendar.css/wp-content/plugins/event-calendar-timely/dist/embed-calendar.js/wp-content/plugins/event-calendar-timely/dist/embed-calendar.jsevent-calendar-timelytimely-embed-calendar-styletimely-embed-calendar-scriptHTML / DOM Fingerprints
data-srcdata-max-heightTIMELY_PATHTIMELY_PLUGIN_VERSION<div id="timely-embed-calendar-placeholder"