Eventi Asiago.it Security & Risk Analysis

wordpress.org/plugins/eventi-asiago-it

Gli eventi di Asiago.it direttamente nel tuo WordPress.

0 active installs v1.1.4 PHP + WP 4.6.1+ Updated Nov 5, 2019
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Eventi Asiago.it Safe to Use in 2026?

Generally Safe

Score 85/100

Eventi Asiago.it has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "eventi-asiago-it" v1.1.4 plugin exhibits a generally positive security posture with no recorded vulnerabilities or critical code signals. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. The plugin also demonstrates good practices in its limited attack surface, with all identified entry points (a single shortcode) not explicitly protected by authentication or capability checks, but given the lack of other entry points and the absence of taint analysis findings, this might indicate a well-contained functionality.

However, there are areas for improvement. The 52% rate of properly escaped output is a concern, as it suggests a significant portion of user-facing data might be vulnerable to cross-site scripting (XSS) attacks. The absence of nonce checks and capability checks, while not leading to immediate critical issues in the static analysis, represents a potential weakness if the shortcode's functionality were to be expanded or if it interacts with user-supplied data in ways not immediately apparent. The lack of any taint analysis data could mean the analysis tools were not configured to perform it, or that the code structure did not lend itself to such analysis, which might hide subtle vulnerabilities.

Overall, the plugin appears to be reasonably secure for its current version and scope, primarily due to the lack of known vulnerabilities and dangerous code patterns. The main risk lies in the unescaped output, which could be exploited by attackers. Strengthening output escaping and potentially implementing more robust access controls, even for seemingly simple shortcodes, would further enhance its security.

Key Concerns

  • Significant portion of output not properly escaped
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Eventi Asiago.it Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Eventi Asiago.it Release Timeline

v1.1.4Current
v1.1.3
v1.1.2
v1.1.1
v1.1
v1.0
Code Analysis
Analyzed Apr 16, 2026

Eventi Asiago.it Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

52% escaped25 total outputs
Attack Surface

Eventi Asiago.it Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[asiagoevents] webcloud-asiago-events.php:42
WordPress Hooks 3
actionadmin_menuwebcloud-asiago-events.php:120
actionadmin_initwebcloud-asiago-events.php:121
actionwidgets_initwebcloud-asiago-events.php:237
Maintenance & Trust

Eventi Asiago.it Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedNov 5, 2019
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

Eventi Asiago.it Alternatives

No alternatives data available yet.

Developer Profile

Eventi Asiago.it Developer Profile

wcmatteo

2 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Eventi Asiago.it

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
webcloud-asiago-events-widget
Data Attributes
id="webcloud_asiago_events_widget"id="api-key"name="webcloud_asiago_events_options[api_key]"id="filter_by_customer"name="webcloud_asiago_events_options[filter_by_customer]"
Shortcode Output
[asiagoevents]
FAQ

Frequently Asked Questions about Eventi Asiago.it