Event Importer for Meetup and The Events Calendar Security & Risk Analysis

wordpress.org/plugins/event-importer-for-meetup-and-the-events-calendar

Automatically import events from Meetup.com into The Events Calendar.

10 active installs v0.3.1 PHP + WP 4.4+ Updated Aug 21, 2016
calendareventsmeetup
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Event Importer for Meetup and The Events Calendar Safe to Use in 2026?

Generally Safe

Score 85/100

Event Importer for Meetup and The Events Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The plugin "event-importer-for-meetup-and-the-events-calendar" v0.3.1 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and a lack of recorded vulnerabilities are positive indicators. Furthermore, the plugin avoids common attack vectors like AJAX handlers, REST API routes, and shortcodes without proper authentication or authorization checks.

However, there are areas for improvement. The low percentage of properly escaped output (60%) indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, particularly if sensitive data is being displayed. While the plugin performs an external HTTP request, the static analysis doesn't reveal if this request is made in a secure manner or if it's susceptible to manipulation. The limited number of nonce and capability checks, especially with the presence of a cron event, suggests that some actions might not be adequately protected against unauthorized execution.

Given the lack of historical vulnerabilities, it's difficult to draw conclusions about past security practices. The current analysis shows a conscious effort to avoid obvious pitfalls. The overall security is decent, with strengths in preventing direct code execution and SQL injection. The primary concern lies in the potential for XSS due to insufficient output escaping, and a need for more robust checks on the cron event and external requests.

Key Concerns

  • Insufficient output escaping
  • One external HTTP request without further analysis
  • Limited nonce and capability checks
Vulnerabilities
None known

Event Importer for Meetup and The Events Calendar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Event Importer for Meetup and The Events Calendar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
6 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

60% escaped10 total outputs
Attack Surface

Event Importer for Meetup and The Events Calendar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 18
actioninitincludes\class-add-new-import.php:46
actionadmin_noticesincludes\class-add-new-import.php:47
actionadmin_noticesincludes\class-add-new-import.php:120
actioninitincludes\class-cpt.php:28
actionsave_post_tec_meetup_importincludes\class-cron.php:36
actiondelete_postincludes\class-cron.php:37
actioninitincludes\class-delete-import.php:36
actionadmin_noticesincludes\class-delete-import.php:65
filterthe_contentincludes\class-event-display.php:36
filtertribe_import_tabsincludes\class-import-settings.php:36
actiontribe_import_general_settingsincludes\class-import-settings.php:38
filtertribe_import_available_optionsincludes\class-import-settings.php:39
filtertribe_field_output_textincludes\class-import-settings.php:40
actiontec_meetup_do_importincludes\class-importer.php:306
actionadmin_enqueue_scriptstec-meetup.php:253
actionall_admin_noticestec-meetup.php:268
actionadmin_inittec-meetup.php:271
actionplugins_loadedtec-meetup.php:398

Scheduled Events 1

tec_meetup_do_import
Maintenance & Trust

Event Importer for Meetup and The Events Calendar Maintenance & Trust

Maintenance Signals

WordPress version tested4.6.30
Last updatedAug 21, 2016
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Event Importer for Meetup and The Events Calendar Developer Profile

dabernathy89

3 plugins · 530 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Event Importer for Meetup and The Events Calendar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/event-importer-for-meetup-and-the-events-calendar/assets/css/tec-meetup.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Event Importer for Meetup and The Events Calendar