
Event Organiser Security & Risk Analysis
wordpress.org/plugins/event-organiserCreate and maintain events, including complex reoccurring patterns, venue management (with Google Maps or OpenStreetMap), calendars and customisable e …
Is Event Organiser Safe to Use in 2026?
Mostly Safe
Score 70/100Event Organiser is generally safe to use though it hasn't been updated recently. 1 past CVE were resolved.
The "event-organiser" plugin version 3.12.8 exhibits a mixed security posture. While it demonstrates good practices in SQL query preparation (69%) and output escaping (68%), and implements a reasonable number of nonce and capability checks, there are significant concerns related to its attack surface and historical vulnerabilities. A notable portion of its AJAX handlers (8 out of 11) lack authentication checks, presenting a broad entry point for potential attacks. The presence of the `unserialize` function, coupled with taint analysis revealing 3 high-severity flows with unsanitized paths, further amplifies these concerns, suggesting potential for remote code execution or data manipulation if these flows are reachable without proper validation.
The plugin's vulnerability history, though appearing to have a single medium-severity CVE, is problematic due to its recency (December 2025) and the fact that it is currently unpatched. This indicates a persistent security weakness that has not been addressed, and the common vulnerability type of 'Missing Authorization' aligns with the static analysis findings of unprotected AJAX handlers. While the plugin has strengths in secure coding practices for SQL and output, the combination of a large unprotected attack surface, the dangerous `unserialize` function, high-severity unsanitized taint flows, and an unpatched historical vulnerability creates a concerning risk profile.
Key Concerns
- Unpatched CVE found
- High severity unsanitized taint flows (3)
- Large attack surface without auth (8 AJAX)
- Dangerous function used (unserialize)
- SQL queries not always prepared
- Output escaping not fully proper
Event Organiser Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Event Organiser <= 3.12.8 - Missing Authorization
Event Organiser Release Timeline
Event Organiser Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Event Organiser Attack Surface
AJAX Handlers 11
Shortcodes 5
WordPress Hooks 118
Scheduled Events 1
Maintenance & Trust
Event Organiser Maintenance & Trust
Maintenance Signals
Community Trust
Event Organiser Alternatives
Timetable and Event Schedule by MotoPress
mp-timetable
Smart event organizer and time-management tool with a clean minimalist design for featuring your timetables and upcoming events.
The Events Calendar Shortcode & Block
the-events-calendar-shortcode
Add shortcode, block, Elementor and Bricks functionality to The Events Calendar Plugin, so you can easily list and promote your events anywhere.
Events Widgets For Elementor And The Events Calendar
events-widgets-for-elementor-and-the-events-calendar
The Events Calendar Elementor widgets help you manage and display an upcoming events list with date, time, venue and event ticket booking details.
Events Shortcodes For The Events Calendar
template-events-calendar
Add The Events Calendar shortcode or Gutenberg block to show upcoming events list with event details on any WordPress page using smart event filters.
WP FullCalendar
wp-fullcalendar
Uses the FullCalendar library to create a stunning calendar view of events, posts and other custom post types
Event Organiser Developer Profile
7 plugins · 23K total installs
How We Detect Event Organiser
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/event-organiser/css/admin-colours.css/wp-content/plugins/event-organiser/css/admin-colours.css/wp-content/plugins/event-organiser/css/admin-notices.css/wp-content/plugins/event-organiser/css/admin-notices.css/wp-content/plugins/event-organiser/css/eo-admin-calendar.css/wp-content/plugins/event-organiser/css/eo-admin-calendar.css/wp-content/plugins/event-organiser/css/eo-admin-styles.css/wp-content/plugins/event-organiser/css/eo-admin-styles.css+116 moreHTML / DOM Fingerprints
eo-admin-noticeeo-event-metaeo-event-scheduleeo-event-schedule-dateeo-event-schedule-timeeo-event-venueeo-event-venue-detailseo-event-venue-location+92 moreCopyright 2011 Stephen Harris (contact@stephenharris.info) This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or+39 moredata-eo-datedata-eo-location-latdata-eo-location-lngdata-eo-map-providerdata-eo-venue-iddata-event-id+15 moreeventorganiser_admin_optionseventorganiser_ajax_objecteventorganiser_venues_listeo_admin_calendar_varseo_admin_notices_varseo_admin_vars+5 more[eo_events[eo_calendar[eo_venues