Eventim US Event Listings Security & Risk Analysis

wordpress.org/plugins/eventim-us-event-listings

Display and manage event listings with advanced customization options, powered by Eventim US.

0 active installs v0.36.1 PHP 8.1+ WP 5.7+ Updated Feb 11, 2026
calendarevent-listingsevent-managementeventstickets
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Eventim US Event Listings Safe to Use in 2026?

Generally Safe

Score 100/100

Eventim US Event Listings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The 'eventim-us-event-listings' plugin v0.36.1 exhibits a generally strong security posture based on the provided static analysis. The code demonstrates excellent adherence to secure coding practices, with 100% of SQL queries using prepared statements and all output being properly escaped. The absence of critical or high severity taint flows further reinforces this positive assessment. The plugin also benefits from thorough security checks, including 11 nonce checks and 5 capability checks, and a minimal attack surface with all 8 AJAX handlers appearing to have authentication mechanisms in place.

While the static analysis reveals no immediate vulnerabilities, and the plugin has no recorded CVEs, a few areas warrant consideration for a complete risk assessment. The presence of 29 file operations, while not explicitly flagged as problematic, could represent potential vectors if not handled with extreme care, especially if user-supplied data is involved in any file path construction. Similarly, the single external HTTP request, though common, should be monitored for potential vulnerabilities within the target endpoint.

Overall, the plugin appears to be developed with security in mind, utilizing many best practices. The lack of historical vulnerabilities further supports this. However, as with any software, continuous monitoring and adherence to security updates are crucial. The strengths lie in its robust input sanitization and output escaping, while potential (though unconfirmed) risks lie in the complex interactions of file operations.

Vulnerabilities
None known

Eventim US Event Listings Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Eventim US Event Listings Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
23 prepared
Unescaped Output
0
507 escaped
Nonce Checks
11
Capability Checks
5
File Operations
29
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared23 total queries

Output Escaping

100% escaped507 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
<event-search> (includes\shortcodes\event-search.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Eventim US Event Listings Attack Surface

Entry Points8
Unprotected0

AJAX Handlers 8

authwp_ajax_evusel_get_default_event_imageincludes\helpers.php:186
authwp_ajax_evusel_convert_to_webpincludes\helpers.php:838
authwp_ajax_evusel_get_events_search_resultsincludes\shortcodes\event-search.php:258
noprivwp_ajax_evusel_get_events_search_resultsincludes\shortcodes\event-search.php:259
authwp_ajax_evusel_list_view_eventsincludes\shortcodes\list-view.php:242
noprivwp_ajax_evusel_list_view_eventsincludes\shortcodes\list-view.php:243
authwp_ajax_evusel_fetch_past_eventsincludes\shortcodes\past-events.php:133
noprivwp_ajax_evusel_fetch_past_eventsincludes\shortcodes\past-events.php:134
WordPress Hooks 35
actionwp_enqueue_scriptseventim-us-event-listings.php:29
actionadmin_enqueue_scriptseventim-us-event-listings.php:30
actionwp_headeventim-us-event-listings.php:47
actionadmin_post_save_see_settingseventim-us-event-listings.php:67
actionadmin_noticeseventim-us-event-listings.php:71
actionadmin_enqueue_scriptseventim-us-event-listings.php:74
actionbefore_delete_posteventim-us-event-listings.php:327
filteracf/settings/save_jsonincludes\acf-fields.php:11
filteracf/settings/load_jsonincludes\acf-fields.php:23
filtercron_schedulesincludes\cron.php:10
actionevusel_cron_hookincludes\cron.php:45
actionrest_api_initincludes\cron.php:54
filterheartbeat_sendincludes\cron.php:562
filterheartbeat_settingsincludes\cron.php:576
actionadmin_menuincludes\evusel-dashboard.php:10
actioninitincludes\evusel-event-post-type.php:78
actioninitincludes\evusel-event-post-type.php:104
actioninitincludes\evusel-event-post-type.php:130
filtermanage_seetickets-event_posts_columnsincludes\evusel-event-post-type.php:154
actionmanage_seetickets-event_posts_custom_columnincludes\evusel-event-post-type.php:189
filtermanage_edit-seetickets-event_sortable_columnsincludes\evusel-event-post-type.php:201
actionpre_get_postsincludes\evusel-event-post-type.php:215
actionadd_meta_boxesincludes\evusel-event-post-type.php:596
filterparse_queryincludes\evusel-event-post-type.php:612
actionbefore_delete_postincludes\evusel-event-post-type.php:629
filterwp_count_postsincludes\evusel-event-post-type.php:700
actionpost_updatedincludes\evusel-event-post-type.php:736
actionacf/save_postincludes\evusel-event-post-type.php:752
filterviews_edit-seetickets-eventincludes\evusel-event-post-type.php:854
filterposts_resultsincludes\evusel-event-post-type.php:892
filterthe_contentincludes\evusel-event-post-type.php:995
filteracf/prepare_fieldincludes\helpers.php:330
filteracf/update_valueincludes\helpers.php:375
filterposts_joinincludes\helpers.php:1077
filterposts_whereincludes\helpers.php:1133

Scheduled Events 1

evusel_cron_hook
Maintenance & Trust

Eventim US Event Listings Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 11, 2026
PHP min version8.1
Downloads78

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Eventim US Event Listings Developer Profile

Eventim US

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Eventim US Event Listings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eventim-us-event-listings/js/evusel-menu.js/wp-content/plugins/eventim-us-event-listings/css/vendor/spectrum.css/wp-content/plugins/eventim-us-event-listings/css/seetickets-admin-custom-styles.css/wp-content/plugins/eventim-us-event-listings/js/vendor/spectrum.js/wp-content/plugins/eventim-us-event-listings/js/vendor/jquery-sortable.min.js/wp-content/plugins/eventim-us-event-listings/js/evusel-admin-custom-scripts.js/wp-content/plugins/eventim-us-event-listings/css/vendor/material-components-web.min.css/wp-content/plugins/eventim-us-event-listings/js/vendor/material-components-web.min.js+6 more
Script Paths
/wp-content/plugins/eventim-us-event-listings/js/evusel-menu.js/wp-content/plugins/eventim-us-event-listings/js/vendor/spectrum.js/wp-content/plugins/eventim-us-event-listings/js/vendor/jquery-sortable.min.js/wp-content/plugins/eventim-us-event-listings/js/evusel-admin-custom-scripts.js/wp-content/plugins/eventim-us-event-listings/js/vendor/material-components-web.min.js/wp-content/plugins/eventim-us-event-listings/js/seetickets-custom-scripts.js+3 more
Version Parameters
eventim-us-event-listings/js/evusel-menu.js?ver=eventim-us-event-listings/css/vendor/spectrum.css?ver=eventim-us-event-listings/css/seetickets-admin-custom-styles.css?ver=eventim-us-event-listings/js/vendor/spectrum.js?ver=eventim-us-event-listings/js/vendor/jquery-sortable.min.js?ver=eventim-us-event-listings/js/evusel-admin-custom-scripts.js?ver=eventim-us-event-listings/css/vendor/material-components-web.min.css?ver=eventim-us-event-listings/js/vendor/material-components-web.min.js?ver=eventim-us-event-listings/css/seetickets-custom-styles.css?ver=eventim-us-event-listings/js/seetickets-custom-scripts.js?ver=eventim-us-event-listings/js/vendor/swiper-bundle.min.js?ver=eventim-us-event-listings/js/seetickets-swiper-init.js?ver=eventim-us-event-listings/css/vendor/swiper-bundle.min.css?ver=eventim-us-event-listings/js/see-calendar.js?ver=

HTML / DOM Fingerprints

CSS Classes
evusel-admin-custom-stylesevusel-custom-stylesevusel-custom-scriptsevuselSliderSettingssee-calendar-js
Data Attributes
evusel_ajax_objevuselSliderSettings
JS Globals
evusel_ajax_objevuselSliderSettings
FAQ

Frequently Asked Questions about Eventim US Event Listings