
Events Calendar Plus Security & Risk Analysis
wordpress.org/plugins/events-calendar-plusDisplay a beautiful events calendar with customizable views, coloring, filtering, date formats, images, and optimized for mobile on your own website.
Is Events Calendar Plus Safe to Use in 2026?
Generally Safe
Score 100/100Events Calendar Plus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "events-calendar-plus" v1.0.13 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices in several areas, including a high percentage of properly escaped outputs and a substantial portion of SQL queries utilizing prepared statements. The absence of any recorded vulnerabilities (CVEs) and taint analysis indicating no critical or high severity issues suggests a generally well-maintained codebase. Furthermore, the plugin does not rely on bundled libraries, which can often become outdated and introduce vulnerabilities.
However, there are significant security concerns stemming from the attack surface. The plugin exposes three AJAX handlers that lack authentication checks. This is a critical weakness, as it allows any unauthenticated user to potentially interact with these handlers, leading to unintended actions or information disclosure if the handlers perform sensitive operations. The presence of unprotected entry points on this scale warrants careful attention. While the plugin does incorporate some capability checks and nonce checks, their absence on all AJAX handlers leaves a substantial gap.
In conclusion, while the plugin benefits from a clean vulnerability history and good coding practices in output escaping and SQL sanitization, the unprotected AJAX handlers represent a serious risk. This plugin would be considered moderately secure but with a significant, exploitable flaw that needs immediate remediation.
Key Concerns
- Unprotected AJAX handlers
- Large attack surface without auth checks
Events Calendar Plus Security Vulnerabilities
Events Calendar Plus Code Analysis
SQL Query Safety
Output Escaping
Events Calendar Plus Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 28
Maintenance & Trust
Events Calendar Plus Maintenance & Trust
Maintenance Signals
Community Trust
Events Calendar Plus Alternatives
The Events Calendar
the-events-calendar
The Events Calendar: #1 calendar plugin for WordPress. Create/manage events (virtual too!) on your site with the free plugin.
Events Calendar for GeoDirectory
events-for-geodirectory
Events Calendar add-on for GeoDirectory allows to extend your GeoDirectory powered website with a versatile event manager.
Pretty Grid – WordPress Images Gallery, Slider, and Carousel Plugin
pretty-grid
Pretty Grid is a flexible plugin that make you display social media content in WordPress.
Crowdcue
crowdcue
Crowdcue is the unofficial OccasionGenius WordPress plugin allows you to easily output a beautiful and simple events page without any coding using the …
Events: Calendar, Boxes, and List
fsdpe-events
A simple and powerful events manager plugin with multiple views: calendar, boxes, and list.
Events Calendar Plus Developer Profile
2 plugins · 750 total installs
How We Detect Events Calendar Plus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/events-calendar-plus/src/admin/assets/calendar-plus-admin.css/wp-content/plugins/events-calendar-plus/src/admin/assets/calendar-plus-admin.js/wp-content/plugins/events-calendar-plus/src/admin/assets/calendar-plus-admin.jsevents-calendar-plus/src/admin/assets/calendar-plus-admin.css?ver=events-calendar-plus/src/admin/assets/calendar-plus-admin.js?ver=HTML / DOM Fingerprints
events-calendar-plus-admin