
EventsFrame Connector Security & Risk Analysis
wordpress.org/plugins/eventsframe-connectorEventsFrame connector plugin let's you connect your EventsFrame account and have your Event's landing page exist also on your WordPress site …
Is EventsFrame Connector Safe to Use in 2026?
Generally Safe
Score 85/100EventsFrame Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The eventsframe-connector v1.04 plugin exhibits a generally positive security posture based on the provided static analysis and vulnerability history. The absence of any identified CVEs, coupled with the lack of critical or high-severity findings in taint analysis, suggests a developer who is mindful of common security pitfalls. The plugin also demonstrates good practices in its handling of SQL queries, exclusively using prepared statements, and by performing capability checks on its limited entry points.
However, a significant concern arises from the low percentage of properly escaped output (31%). This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, where user-supplied or dynamic data displayed by the plugin might not be sufficiently sanitized, allowing attackers to inject malicious scripts. Furthermore, the lack of nonce checks on AJAX handlers (though there are no AJAX handlers in this version) and the absence of any identified attack surface, while seemingly good, could also suggest a very limited functionality or an incomplete static analysis. The presence of external HTTP requests without further context also warrants caution, as these could be vectors for various attacks if not handled securely.
In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL practices, the poor output escaping is a notable weakness that significantly elevates the risk of XSS. The plugin's strengths lie in its absence of known exploits and secure database interactions, but this is undermined by the potential for client-side vulnerabilities due to insufficient output sanitization.
Key Concerns
- Low output escaping percentage (31%)
- No nonce checks on AJAX handlers
EventsFrame Connector Security Vulnerabilities
EventsFrame Connector Release Timeline
EventsFrame Connector Code Analysis
Output Escaping
EventsFrame Connector Attack Surface
WordPress Hooks 11
Maintenance & Trust
EventsFrame Connector Maintenance & Trust
Maintenance Signals
Community Trust
EventsFrame Connector Alternatives
Events Addon for Elementor
events-addon-for-elementor
Events Addon for Elementor is an Elementor Addons for Event Websites.
Ticket Tailor — Event Ticketing & Registration
ticket-tailor
Sell event tickets online via your WordPress website. Ticket Tailor is an easy event ticketing & event registration system.
TicketSource Ticket Shop
ticketsource-events
Sell event tickets online directly through your WordPress site with TicketSource. An easy to use, self service box office system.
Import Meetup Events – Meetup Sync & Event Aggregator for WordPress
import-meetup-events
Automatically import and sync Meetup.com events into WordPress without a Meetup Pro account. Works with The Events Calendar, Events Manager, EventON, …
Eveeno
eveeno
WordPress plugin for embedding eveeno registration forms and upcoming events lists.
EventsFrame Connector Developer Profile
1 plugin · 10 total installs
How We Detect EventsFrame Connector
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/eventsframe-connector/includes/front/style.css/wp-content/plugins/eventsframe-connector/includes/front/script.jseventsframe-connector/includes/front/style.css?ver=eventsframe-connector/includes/front/script.js?ver=