
EventsCalendar.co Events Calendar Security & Risk Analysis
wordpress.org/plugins/eventscalendar-coDisplay events in multiple views with RSVPs, event submissions, and timezone settings. Sync with Google, Outlook, Eventbrite, Zoom, or any iCal feed.
Is EventsCalendar.co Events Calendar Safe to Use in 2026?
Generally Safe
Score 100/100EventsCalendar.co Events Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "eventscalendar-co" v1.1.1 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, unescaped output, and file operations are significant strengths. The use of prepared statements for all SQL queries and proper output escaping further reinforces this positive assessment. The plugin also demonstrates awareness of security best practices by implementing nonce checks for its entry points. Furthermore, its vulnerability history is clean, with no known CVEs, suggesting a commitment to security or a lack of past exploitable issues.
However, a notable concern arises from the lack of capability checks on its identified entry points. While nonce checks are present, relying solely on them without proper authorization checks can leave the plugin vulnerable to privilege escalation or unauthorized access if an attacker can bypass or manipulate the nonce mechanism. The presence of external HTTP requests also warrants cautious monitoring, though without further context on what these requests are for, it's difficult to assign a definitive risk. Overall, the plugin has a solid foundation, but the absence of capability checks introduces a point of weakness that should be addressed to achieve a truly robust security profile.
Key Concerns
- Missing capability checks on entry points
EventsCalendar.co Events Calendar Security Vulnerabilities
EventsCalendar.co Events Calendar Release Timeline
EventsCalendar.co Events Calendar Code Analysis
Output Escaping
Data Flow Analysis
EventsCalendar.co Events Calendar Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
EventsCalendar.co Events Calendar Maintenance & Trust
Maintenance Signals
Community Trust
EventsCalendar.co Events Calendar Alternatives
Events Calendar by AddEvent – Embeddable Event Calendar Plugin
addevent
Easily embed your events calendar on your WordPress site with AddEvent's embeddable calendar plugin.
Events Widgets For Elementor And The Events Calendar
events-widgets-for-elementor-and-the-events-calendar
The Events Calendar Elementor widgets help you manage and display an upcoming events list with date, time, venue and event ticket booking details.
Sugar Calendar – Events Calendar, Event Tickets, and Events Management Platform
sugar-calendar-lite
Easily manage events and sell tickets on your WordPress site. Sugar Calendar is easy-to-use, reliable, and exceptionally powerful. See for yourself.
Events Shortcodes For The Events Calendar
template-events-calendar
Add The Events Calendar shortcode or Gutenberg block to show upcoming events list with event details on any WordPress page using smart event filters.
WP FullCalendar
wp-fullcalendar
Uses the FullCalendar library to create a stunning calendar view of events, posts and other custom post types
EventsCalendar.co Events Calendar Developer Profile
1 plugin · 60 total installs
How We Detect EventsCalendar.co Events Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eventscalendar-co/block/build/index.js/wp-content/plugins/eventscalendar-co/block/build/index.asset.php/wp-content/plugins/eventscalendar-co/assets/block-editor.csshttps://dist.eventscalendar.co/embed.js//dist.eventscalendar.co/embed.js/wp-content/plugins/eventscalendar-co/block/src/options.jseventscalendar-co/style.css?ver=eventscalendar-co__block_editor_jseventscalendar-co-embed-scriptHTML / DOM Fingerprints
eventscalendar.co-widgeteventscalendarco-widgetdata-events-calendar-appdata-project-iddata-embed-origineventsCalendarCoOptions<div data-events-calendar-app data-project-id="" data-embed-origin="elementor-widget"></div>