EventsCalendar.co Events Calendar Security & Risk Analysis

wordpress.org/plugins/eventscalendar-co

Display events in multiple views with RSVPs, event submissions, and timezone settings. Sync with Google, Outlook, Eventbrite, Zoom, or any iCal feed.

60 active installs v1.1.1 PHP 7.0+ WP 5.0+ Updated Sep 7, 2025
calendarembedevent-calendarevents
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EventsCalendar.co Events Calendar Safe to Use in 2026?

Generally Safe

Score 100/100

EventsCalendar.co Events Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "eventscalendar-co" v1.1.1 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, unescaped output, and file operations are significant strengths. The use of prepared statements for all SQL queries and proper output escaping further reinforces this positive assessment. The plugin also demonstrates awareness of security best practices by implementing nonce checks for its entry points. Furthermore, its vulnerability history is clean, with no known CVEs, suggesting a commitment to security or a lack of past exploitable issues.

However, a notable concern arises from the lack of capability checks on its identified entry points. While nonce checks are present, relying solely on them without proper authorization checks can leave the plugin vulnerable to privilege escalation or unauthorized access if an attacker can bypass or manipulate the nonce mechanism. The presence of external HTTP requests also warrants cautious monitoring, though without further context on what these requests are for, it's difficult to assign a definitive risk. Overall, the plugin has a solid foundation, but the absence of capability checks introduces a point of weakness that should be addressed to achieve a truly robust security profile.

Key Concerns

  • Missing capability checks on entry points
Vulnerabilities
None known

EventsCalendar.co Events Calendar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

EventsCalendar.co Events Calendar Release Timeline

v1.1.1Current
Code Analysis
Analyzed Mar 16, 2026

EventsCalendar.co Events Calendar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
27 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

100% escaped27 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
eventscalendar_co__add_menu (src\menu.php:88)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

EventsCalendar.co Events Calendar Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_eventscalendar_co__calendars_updatesrc\ajax.php:36

Shortcodes 1

[eventscalendar-co] src\shortcode.php:35
WordPress Hooks 11
actioninitblock\eventscalendar.php:17
actionafter_setup_themeblock\eventscalendar.php:65
actionenqueue_block_editor_assetsblock\eventscalendar.php:99
actionenqueue_block_editor_assetssrc\editor.php:16
actionelementor/widgets/widgets_registeredsrc\elementorWidget.php:120
actionelementor/initsrc\elementorWidget.php:126
actionelementor/editor/after_enqueue_stylessrc\elementorWidget.php:137
actionadmin_menusrc\menu.php:86
actionadmin_enqueue_scriptssrc\menu.php:327
actionadmin_enqueue_scriptssrc\menu.php:348
actionwidgets_initsrc\widget.php:12
Maintenance & Trust

EventsCalendar.co Events Calendar Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.6
Last updatedSep 7, 2025
PHP min version7.0
Downloads713

Community Trust

Rating100/100
Number of ratings2
Active installs60
Developer Profile

EventsCalendar.co Events Calendar Developer Profile

EventsCalendar.co

1 plugin · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect EventsCalendar.co Events Calendar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eventscalendar-co/block/build/index.js/wp-content/plugins/eventscalendar-co/block/build/index.asset.php/wp-content/plugins/eventscalendar-co/assets/block-editor.css
Script Paths
https://dist.eventscalendar.co/embed.js//dist.eventscalendar.co/embed.js/wp-content/plugins/eventscalendar-co/block/src/options.js
Version Parameters
eventscalendar-co/style.css?ver=eventscalendar-co__block_editor_jseventscalendar-co-embed-script

HTML / DOM Fingerprints

CSS Classes
eventscalendar.co-widgeteventscalendarco-widget
Data Attributes
data-events-calendar-appdata-project-iddata-embed-origin
JS Globals
eventsCalendarCoOptions
Shortcode Output
<div data-events-calendar-app data-project-id="" data-embed-origin="elementor-widget"></div>
FAQ

Frequently Asked Questions about EventsCalendar.co Events Calendar