Event SEO: Event Schema / Structured Data: Google Rich Snippet Schema for Event Security & Risk Analysis

wordpress.org/plugins/event-schema

Automatically generate Google Event Rich Snippet Schema (JSON-LD) for events using popular calendar plugins.

700 active installs v1.1.4 PHP 5.4+ WP 4.0+ Updated Nov 29, 2025
eventevent-rich-snippetsgoogle-schemaschemaseo
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Event SEO: Event Schema / Structured Data: Google Rich Snippet Schema for Event Safe to Use in 2026?

Generally Safe

Score 100/100

Event SEO: Event Schema / Structured Data: Google Rich Snippet Schema for Event has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "event-schema" plugin v1.1.4 exhibits a generally strong security posture, with a notable absence of known vulnerabilities and a commendable use of prepared statements for all SQL queries. The static analysis shows a very small attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events exposed. Code quality is high, with nearly all output properly escaped and no dangerous functions or file operations detected.

However, the taint analysis reveals two flows with unsanitized paths, both classified as high severity. While the plugin has no history of public vulnerabilities, these high-severity taint flows represent a significant concern that warrants attention. The lack of capability checks on any entry points, though the attack surface is currently zero, could become a risk if functionality is added in the future without proper authorization.

In conclusion, "event-schema" v1.1.4 is well-coded with good security practices in place, particularly concerning database interactions and output escaping. The main area of concern lies within the identified high-severity taint flows. Addressing these should be the priority. The plugin's clean vulnerability history is a positive sign, but the presence of these internal risks suggests a need for thorough code review and remediation before assuming complete security.

Key Concerns

  • High severity taint flows found
  • Two flows with unsanitized paths
  • No capability checks on entry points
Vulnerabilities
None known

Event SEO: Event Schema / Structured Data: Google Rich Snippet Schema for Event Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Event SEO: Event Schema / Structured Data: Google Rich Snippet Schema for Event Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
10 prepared
Unescaped Output
8
91 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared10 total queries

Output Escaping

92% escaped99 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
handle_schema_settings_submit (includes\class-event-schema-common.php:38)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Event SEO: Event Schema / Structured Data: Google Rich Snippet Schema for Event Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 23
actionplugins_loadedevent-schema.php:54
actionadmin_menuincludes\class-event-schema-admin.php:41
actionadmin_enqueue_scriptsincludes\class-event-schema-admin.php:42
actionadmin_noticesincludes\class-event-schema-admin.php:43
filteradmin_footer_textincludes\class-event-schema-admin.php:44
actionwp_dashboard_setupincludes\class-event-schema-admin.php:45
actionwp_footerincludes\class-event-schema-aioec.php:38
actionadmin_initincludes\class-event-schema-common.php:31
actionwp_footerincludes\class-event-schema-em.php:51
actionwp_footerincludes\class-event-schema-eventon.php:32
actionwp_footerincludes\class-event-schema-event_organizer.php:38
actionwp_footerincludes\class-event-schema-iee.php:37
actioniee_after_event_listincludes\class-event-schema-iee.php:38
actioniee_after_widget_event_listincludes\class-event-schema-iee.php:39
actionwp_footerincludes\class-event-schema-ife.php:37
actionife_after_event_listincludes\class-event-schema-ife.php:38
actionife_after_widget_event_listincludes\class-event-schema-ife.php:39
actionwp_footerincludes\class-event-schema-ime.php:37
actionime_after_event_listincludes\class-event-schema-ime.php:38
actionime_after_widget_event_listincludes\class-event-schema-ime.php:39
actionwp_footerincludes\class-event-schema-wpea.php:37
actionwpea_after_event_listincludes\class-event-schema-wpea.php:38
actionwpea_after_widget_event_listincludes\class-event-schema-wpea.php:39
Maintenance & Trust

Event SEO: Event Schema / Structured Data: Google Rich Snippet Schema for Event Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 29, 2025
PHP min version5.4
Downloads17K

Community Trust

Rating100/100
Number of ratings5
Active installs700
Developer Profile

Event SEO: Event Schema / Structured Data: Google Rich Snippet Schema for Event Developer Profile

Xylus Themes

13 plugins · 110K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
105 days
View full developer profile
Detection Fingerprints

How We Detect Event SEO: Event Schema / Structured Data: Google Rich Snippet Schema for Event

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/event-schema/assets/css/event-schema-admin.css/wp-content/plugins/event-schema/assets/js/event-schema-admin.js
Script Paths
/wp-content/plugins/event-schema/assets/js/event-schema-admin.js
Version Parameters
event-schema-admin.css?ver=event-schema-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Event SEO: Event Schema / Structured Data: Google Rich Snippet Schema for Event