
Evento Security & Risk Analysis
wordpress.org/plugins/eventoEnhance EventPress WordPress Themes Functionality.
Is Evento Safe to Use in 2026?
Generally Safe
Score 92/100Evento has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "evento" v2.5 plugin exhibits a generally strong security posture based on the static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication or permission checks, combined with zero critical or high severity taint flows, suggests a minimal attack surface. The plugin also utilizes prepared statements exclusively for SQL queries and has no recorded vulnerabilities, indicating a history of security consciousness. However, a significant concern arises from the output escaping: only 54% of outputs are properly escaped. This means over half of the plugin's outputting functions may be susceptible to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not sanitized before display. While the plugin has a clean vulnerability history, the high percentage of unescaped output presents a tangible risk that warrants immediate attention.
Key Concerns
- High percentage of unescaped output
Evento Security Vulnerabilities
Evento Release Timeline
Evento Code Analysis
Output Escaping
Evento Attack Surface
WordPress Hooks 41
Maintenance & Trust
Evento Maintenance & Trust
Maintenance Signals
Community Trust
Evento Alternatives
Clever Fox
clever-fox
Clever Fox plugin to enhance the functionality of free themes made by Nayra Themes.
eCommerce Companion
ecommerce-companion
eCommerce Companion plugin only for Seller Themes. Its fully WooCommerce Compatible Themes
Specia Companion
specia-companion
Specia Companion is created for Specia Theme
Reset Customizer
reset-customizer
Adds a reset button to each section in the customizer and easily backup / restore / migrate customizer settings
Kirki Customizer Framework
kirki
The Ultimate Customizer Framework for WordPress Theme Developers
Evento Developer Profile
72 plugins · 54K total installs
How We Detect Evento
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/evento/inc/custom-controls/range-validator/assets/css/range-control.css/wp-content/plugins/evento/inc/custom-controls/range-validator/assets/js/range-control.js/wp-content/plugins/evento/inc/custom-controls/select/assets/js/select-control.js/wp-content/plugins/evento/inc/custom-controls/select/assets/selectize.default.css/wp-content/plugins/evento/inc/custom-controls/select/assets/js/selectize.min.jsHTML / DOM Fingerprints
evento-rangeevento-range-defievento-range-valueevento-resets-range-valueevento-select-controltype="evento-range"Evento_Customizer_Range_ControlEvento_Customizer_Select_Control