
Event Organiser VAT Security & Risk Analysis
wordpress.org/plugins/event-organiser-vatAdds VAT to booking checkout. Requires Event Organiser & Event Organiser Pro
Is Event Organiser VAT Safe to Use in 2026?
Generally Safe
Score 85/100Event Organiser VAT has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security analysis of the "event-organiser-vat" plugin v1.0.6 reveals a generally strong security posture based on the provided static analysis data. There are no identified dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. Furthermore, the plugin has no recorded vulnerabilities or CVEs, which is a positive indicator of its security over time. The absence of file operations and external HTTP requests also reduces potential attack vectors.
However, a significant concern arises from the complete lack of any capability checks, nonce checks, AJAX handlers, REST API routes, shortcodes, or cron events. While this contributes to a very small attack surface, it suggests that the plugin may not perform any user-facing or background actions that would typically require these security measures. If the plugin is intended to have any interactive or scheduled functionality, this absence could indicate a potential oversight rather than a deliberate minimalistic design. This lack of any entry points that necessitate security checks makes it difficult to fully assess its security in a dynamic context.
In conclusion, the plugin exhibits excellent coding practices regarding data handling and output sanitization, and its historical security record is spotless. The primary weakness lies in the apparent absence of any features that would require typical WordPress security mechanisms like capability or nonce checks, which, while not a direct vulnerability in itself, raises questions about its functionality and completeness. Until more context on the plugin's purpose is available, its security is difficult to fully quantify beyond its well-implemented internal code hygiene.
Key Concerns
- No capability checks implemented
- No nonce checks implemented
Event Organiser VAT Security Vulnerabilities
Event Organiser VAT Code Analysis
Output Escaping
Event Organiser VAT Attack Surface
WordPress Hooks 9
Maintenance & Trust
Event Organiser VAT Maintenance & Trust
Maintenance Signals
Community Trust
Event Organiser VAT Alternatives
No alternatives data available yet.
Event Organiser VAT Developer Profile
6 plugins · 23K total installs
How We Detect Event Organiser VAT
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/event-organiser-vat/assets/js/vat.js/wp-content/plugins/event-organiser-vat/assets/js/vat.min.js/wp-content/plugins/event-organiser-vat/assets/js/vat.js/wp-content/plugins/event-organiser-vat/assets/js/vat.min.jsevent-organiser-vat/assets/js/vat.js?ver=event-organiser-vat/assets/js/vat.min.js?ver=HTML / DOM Fingerprints
eo-booking-vat-roweo_pro_vat