
Event Page Plugin Security & Risk Analysis
wordpress.org/plugins/event-pageThe Event Page Plugin allows you to create a page, category page or post on your wordpress blog that lists all your events sorted in ascending or desc …
Is Event Page Plugin Safe to Use in 2026?
Generally Safe
Score 85/100Event Page Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The event-page plugin v2.7.4 exhibits a mixed security posture. On one hand, it has a very small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events exposed externally. This significantly limits potential entry points for attackers. However, the code analysis reveals several concerning signals. The presence of the `create_function` function is a significant red flag, as it can lead to code execution vulnerabilities if not handled with extreme caution and strict sanitization. Furthermore, none of the SQL queries are parameterized, making them highly susceptible to SQL injection attacks. The low percentage of properly escaped output indicates a high risk of cross-site scripting (XSS) vulnerabilities across various output points.
Taint analysis also highlights critical concerns, with two flows identified as having unsanitized paths, indicating potential for sensitive data exposure or unauthorized actions. While there is no known vulnerability history for this plugin, the internal code signals suggest that vulnerabilities could exist and may have gone unnoticed or unexploited due to the limited attack surface. The plugin demonstrates some security awareness with nonce and capability checks, but these are insufficient to mitigate the risks posed by dangerous functions, raw SQL queries, and poor output escaping.
In conclusion, despite a seemingly secure external attack surface, the internal code quality presents substantial security risks. The lack of prepared statements for all SQL queries and the low rate of output escaping are major weaknesses. The `create_function` usage and unsanitized taint flows are critical concerns that require immediate attention. Users should be wary of this plugin until these issues are addressed.
Key Concerns
- Unsanitized taint flows (High Severity)
- SQL queries without prepared statements
- Low percentage of properly escaped output
- Use of dangerous function 'create_function'
Event Page Plugin Security Vulnerabilities
Event Page Plugin Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Event Page Plugin Attack Surface
WordPress Hooks 18
Maintenance & Trust
Event Page Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Event Page Plugin Alternatives
Calendar
calendar
A simple but effective Calendar plugin for WordPress that allows you to manage your events and appointments and display them to the world.
FT Calendar
ft-calendar
A calendar plugin supporting multiple calendars, recurring events, and several different widgets / shortcodes. More info at http://calendar-plugin.com
Minimalistic Event Manager
minimalistic-event-manager
A simple and flexible solution for managing event dates.
Calendar Plus
calendar-plus
A simple Calendar plugin for WordPress that allows 2 seperate calendars. This can be used as a drop-in replacement for the original Calendar plugin.
Hassle-Free Date List
hassle-free-date-list
This plugin adds a block, a shortcode, and a contactform 7 form tag that displays a list of dates. Dates that are due will automatically be hidden or …
Event Page Plugin Developer Profile
3 plugins · 110 total installs
How We Detect Event Page Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/event-page/css/admin.css/wp-content/plugins/event-page/css/style.cssHTML / DOM Fingerprints
tern_wp_root