Events Calendar for Google Security & Risk Analysis

wordpress.org/plugins/events-calendar-for-google

Events Calendar for Google implements google calender to your wordpress website using different style and layouts. Get connected to your audience usin …

2K active installs v3.2.2 PHP 5.6+ WP 4.5+ Updated Dec 30, 2025
calendereventevent-calendareventsgoogle-calendar
98
A · Safe
CVEs total1
Unpatched0
Last CVEJul 11, 2024
Download
Safety Verdict

Is Events Calendar for Google Safe to Use in 2026?

Generally Safe

Score 98/100

Events Calendar for Google has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jul 11, 2024Updated 3mo ago
Risk Assessment

The 'events-calendar-for-google' plugin version 3.2.2 exhibits a mixed security posture. While it demonstrates good practices like using prepared statements for all SQL queries and a high percentage of properly escaped output, significant concerns arise from its attack surface. A substantial portion of its entry points, specifically 4 out of 5, are not protected by authentication checks. This makes them highly susceptible to unauthorized access and manipulation, especially given the presence of AJAX handlers without authorization.

The vulnerability history reveals a past high-severity CVE related to 'PHP Remote File Inclusion,' which is a critical vulnerability type. Although this vulnerability is currently patched and no unpatched CVEs are present, the nature of the past vulnerability is concerning. The lack of taint analysis data, while potentially indicating no critical flows were found, also means there might be undetected vulnerabilities. The presence of external HTTP requests and only one nonce check also warrants attention. Overall, the plugin has strengths in data handling but significant weaknesses in access control for its entry points, compounded by past critical vulnerability patterns.

Key Concerns

  • High number of unprotected AJAX handlers
  • Past high severity 'PHP Remote File Inclusion' CVE
  • One external HTTP request detected
  • Only 1 nonce check for 5 entry points
Vulnerabilities
1

Events Calendar for Google Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2024-38716high · 8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Events Calendar for Google <= 2.1.0 - Authenticated (Contributor+) Local File Inclusion

Jul 11, 2024 Patched in 3.0.0 (180d)
Code Analysis
Analyzed Mar 16, 2026

Events Calendar for Google Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
92 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

86% escaped107 total outputs
Attack Surface
4 unprotected

Events Calendar for Google Attack Surface

Entry Points5
Unprotected4

AJAX Handlers 4

noprivwp_ajax_ECFG_advance_filter_searchevents_calendar_for_google.php:170
authwp_ajax_ECFG_advance_filter_searchevents_calendar_for_google.php:171
noprivwp_ajax_ECFG_events_paginationevents_calendar_for_google.php:172
authwp_ajax_ECFG_events_paginationevents_calendar_for_google.php:173

Shortcodes 1

[ECFG_calender_events] events_calendar_for_google.php:169
WordPress Hooks 14
actionplugins_loadedevents_calendar_for_google.php:127
actionadmin_enqueue_scriptsevents_calendar_for_google.php:142
actionadmin_enqueue_scriptsevents_calendar_for_google.php:143
actionadmin_menuevents_calendar_for_google.php:146
actionadmin_initevents_calendar_for_google.php:149
actionwp_enqueue_scriptsevents_calendar_for_google.php:166
actionwp_enqueue_scriptsevents_calendar_for_google.php:167
actionwp_footerevents_calendar_for_google.php:168
actionecfg_e_dateevents_calendar_for_google.php:188
actionecfg_e_titleevents_calendar_for_google.php:189
actionecfg_e_descevents_calendar_for_google.php:190
actionecfg_e_locationevents_calendar_for_google.php:191
actionecfg_e_timeevents_calendar_for_google.php:192
actionecfg_e_moreevents_calendar_for_google.php:193
Maintenance & Trust

Events Calendar for Google Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedDec 30, 2025
PHP min version5.6
Downloads47K

Community Trust

Rating84/100
Number of ratings20
Active installs2K
Developer Profile

Events Calendar for Google Developer Profile

Rupinder Kaur

2 plugins · 6K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
180 days
View full developer profile
Detection Fingerprints

How We Detect Events Calendar for Google

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/events-calendar-for-google/admin/css/events-calendar-for-google-admin.css/wp-content/plugins/events-calendar-for-google/public/css/events-calendar-for-google-public.css/wp-content/plugins/events-calendar-for-google/public/js/events-calendar-for-google-public.js
Script Paths
/wp-content/plugins/events-calendar-for-google/public/js/events-calendar-for-google-public.js
Version Parameters
events-calendar-for-google/admin/css/events-calendar-for-google-admin.css?ver=events-calendar-for-google/public/css/events-calendar-for-google-public.css?ver=events-calendar-for-google/public/js/events-calendar-for-google-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
ecfg_events_list
HTML Comments
<!-- START ECFG Google Calender events --><!-- END ECFG Google Calender events -->
Data Attributes
data-ecfg-calendar-iddata-ecfg-event-countdata-ecfg-event-title-colordata-ecfg-event-desc-colordata-ecfg-event-date-colordata-ecfg-event-bg-color+4 more
JS Globals
ECFG_public_data
REST Endpoints
/wp-json/ecfg/v1/events
Shortcode Output
[ECFG_calender_events
FAQ

Frequently Asked Questions about Events Calendar for Google