EventsFrame Connector Security & Risk Analysis

wordpress.org/plugins/eventsframe-connector

EventsFrame connector plugin let's you connect your EventsFrame account and have your Event's landing page exist also on your WordPress site …

10 active installs v1.04 PHP 7.2+ WP + Updated Aug 10, 2020
conferenceeventevent-pagemeetupticketing
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EventsFrame Connector Safe to Use in 2026?

Generally Safe

Score 85/100

EventsFrame Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The eventsframe-connector v1.04 plugin exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of any identified CVEs, coupled with the lack of critical or high-severity findings in taint analysis, suggests a developer who is mindful of common security pitfalls. The plugin also demonstrates good practices in its handling of SQL queries, exclusively using prepared statements, and by performing capability checks on its limited entry points.

However, a significant concern arises from the low percentage of properly escaped output (31%). This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, where user-supplied or dynamic data displayed by the plugin might not be sufficiently sanitized, allowing attackers to inject malicious scripts. Furthermore, the lack of nonce checks on AJAX handlers (though there are no AJAX handlers in this version) and the absence of any identified attack surface, while seemingly good, could also suggest a very limited functionality or an incomplete static analysis. The presence of external HTTP requests without further context also warrants caution, as these could be vectors for various attacks if not handled securely.

In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL practices, the poor output escaping is a notable weakness that significantly elevates the risk of XSS. The plugin's strengths lie in its absence of known exploits and secure database interactions, but this is undermined by the potential for client-side vulnerabilities due to insufficient output sanitization.

Key Concerns

  • Low output escaping percentage (31%)
  • No nonce checks on AJAX handlers
Vulnerabilities
None known

EventsFrame Connector Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

EventsFrame Connector Release Timeline

v1.04Current
v1.03
v1.02
v1.01
Code Analysis
Analyzed Mar 17, 2026

EventsFrame Connector Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
4 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

31% escaped13 total outputs
Attack Surface

EventsFrame Connector Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionset_current_usereventsframe.php:80
actioniniteventsframe.php:81
filtertemplate_includeeventsframe.php:153
actionadmin_initincludes\admin\admin.php:24
actionadmin_initincludes\admin\admin.php:25
actionadmin_menuincludes\admin\admin.php:26
actioncurrent_screenincludes\admin\admin.php:27
actionadmin_print_scriptsincludes\admin\admin.php:28
filterpost_row_actionsincludes\admin\admin.php:31
filterwp_insert_post_dataincludes\admin\admin.php:32
actionadmin_headincludes\admin\admin.php:61
Maintenance & Trust

EventsFrame Connector Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedAug 10, 2020
PHP min version7.2
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

EventsFrame Connector Developer Profile

EventsFrame

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect EventsFrame Connector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eventsframe-connector/includes/front/style.css
Script Paths
/wp-content/plugins/eventsframe-connector/includes/front/script.js
Version Parameters
eventsframe-connector/includes/front/style.css?ver=eventsframe-connector/includes/front/script.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about EventsFrame Connector