Event Date Poll Security & Risk Analysis

wordpress.org/plugins/event-date-poll

A simple sidebar widget that links to Set The Date — a free tool to help groups pick the best date.

0 active installs v1.6.1 PHP 7.2+ WP 5.0+ Updated Unknown
calendareventsgroup-schedulingpollwidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Event Date Poll Safe to Use in 2026?

Generally Safe

Score 100/100

Event Date Poll has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The event-date-poll plugin v1.6.1 exhibits a generally positive security posture based on the provided static analysis. The absence of any known CVEs, along with the lack of critical or high-severity taint flows, suggests a codebase that has been developed with security in mind. The complete reliance on prepared statements for SQL queries and a high percentage of properly escaped output are excellent practices that mitigate common web application vulnerabilities. The minimal attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or permission checks, further strengthens its security. However, the complete lack of nonce checks and capability checks across all identified entry points represents a significant potential weakness. While the current analysis shows no unprotected entry points, this absence of authorization and integrity checks means that if any new entry points were inadvertently introduced or discovered in future versions, they would likely be vulnerable to exploitation. The vulnerability history also shows no recorded issues, which is a strong indicator of good maintenance but doesn't entirely eliminate the possibility of undiscovered flaws. Overall, the plugin is secure in its current state due to good coding practices, but the absence of fundamental security checks on any potential interactions leaves room for improvement.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Event Date Poll Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Event Date Poll Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
32 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

89% escaped36 total outputs
Attack Surface

Event Date Poll Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwidgets_initevent-date-poll.php:16
actionwp_enqueue_scriptsevent-date-poll.php:26
Maintenance & Trust

Event Date Poll Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version7.2
Downloads621

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Event Date Poll Developer Profile

setthedate

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Event Date Poll

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/event-date-poll/assets/set-the-date-widget.css
Version Parameters
event-date-poll/assets/set-the-date-widget.css?ver=1.6.1

HTML / DOM Fingerprints

CSS Classes
set-the-date-ctaset-the-date-logostd-button
Data Attributes
data-field-iddata-field-name
Shortcode Output
<div class="set-the-date-cta"><img src="" alt="Set The Date Logo" class="set-the-date-logo">
FAQ

Frequently Asked Questions about Event Date Poll