
External Events Calendar Security & Risk Analysis
wordpress.org/plugins/external-events-calendarThis plugin adds a basic "upcoming events" calendar of links to Wordpress.
Is External Events Calendar Safe to Use in 2026?
Generally Safe
Score 85/100External Events Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The external-events-calendar plugin version 0.4.0 exhibits a mixed security posture. On the positive side, it boasts a very small attack surface with only one entry point (a shortcode) and no identified CVEs in its history. Furthermore, the absence of file operations and external HTTP requests reduces potential attack vectors. However, several concerning code signals indicate potential weaknesses.
The plugin uses SQL queries, with a significant portion (67%) not employing prepared statements, raising concerns about SQL injection vulnerabilities. The low percentage of properly escaped output (11%) is another major red flag, suggesting a high likelihood of cross-site scripting (XSS) vulnerabilities. Taint analysis reveals flows with unsanitized paths, indicating that user-supplied data might be processed insecurely, although no critical or high severity issues were flagged in this specific analysis.
The lack of vulnerability history is generally positive, but it's crucial to note that this is based on past data. The current analysis highlights systemic issues in input sanitization and output escaping. The absence of nonce checks and capability checks, while not directly tied to an attack vector in this specific analysis due to the limited attack surface, are fundamental security practices that are missing. Overall, while the plugin is not demonstrably vulnerable based on past CVEs and a limited attack surface, the static analysis reveals significant code quality concerns regarding SQL injection and XSS that require immediate attention.
Key Concerns
- SQL queries without prepared statements
- Low percentage of properly escaped output
- Flows with unsanitized paths
- Missing nonce checks
- Missing capability checks
External Events Calendar Security Vulnerabilities
External Events Calendar Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
External Events Calendar Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
External Events Calendar Maintenance & Trust
Maintenance Signals
Community Trust
External Events Calendar Alternatives
Events Widgets For Elementor And The Events Calendar
events-widgets-for-elementor-and-the-events-calendar
The Events Calendar Elementor widgets help you manage and display an upcoming events list with date, time, venue and event ticket booking details.
Upcoming Events Lists
upcoming-events-lists
A WordPress plugin to show a list of upcoming events on the front-end.
Event Calendar by Timely
event-calendar-timely
Attract, engage, and grow your audience with Timely’s free event calendar app. The calendar plugin for WordPress trusted by event managers worldwide.
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
Timetable and Event Schedule by MotoPress
mp-timetable
Smart event organizer and time-management tool with a clean minimalist design for featuring your timetables and upcoming events.
External Events Calendar Developer Profile
3 plugins · 50 total installs
How We Detect External Events Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/external-events-calendar/external-events-calendar.css/wp-content/plugins/external-events-calendar/external-events-calendar.js/wp-content/plugins/external-events-calendar/external-events-calendar.jsexternal-events-calendar/external-events-calendar.css?ver=external-events-calendar/external-events-calendar.js?ver=HTML / DOM Fingerprints
extevtcal-calendardata-extevtcal-dateextevtcal