Files Addon for Event Espresso 4 Security & Risk Analysis

wordpress.org/plugins/files-addon-for-event-espresso-4

Files add on plugin allows to create file upload type question which can be used in event registration form.

40 active installs v1.2.1 PHP + WP 4.1+ Updated Apr 28, 2024
event-espressofileformquestionsupload-file
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Files Addon for Event Espresso 4 Safe to Use in 2026?

Generally Safe

Score 85/100

Files Addon for Event Espresso 4 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "files-addon-for-event-espresso-4" plugin v1.2.1 presents a significant security risk due to its unprotected attack surface. The plugin exposes two AJAX handlers without any authentication or capability checks. This means any user, including unauthenticated ones, could potentially trigger these handlers, leading to unintended actions or information disclosure depending on their implementation. The lack of any taint analysis results is concerning, as it suggests limited or no testing for flows that could lead to vulnerabilities like cross-site scripting or SQL injection, especially when combined with the fact that all SQL queries lack prepared statements and output is not properly escaped. The complete absence of known CVEs and past vulnerabilities is a positive indicator of past security efforts or perhaps a lack of targeted attacks, but it does not mitigate the immediate risks identified in the code analysis. Given the significant number of unprotected entry points and the absence of fundamental security measures like input validation and proper escaping, this plugin should be considered high-risk.

Key Concerns

  • Unprotected AJAX handlers
  • SQL queries without prepared statements
  • Output not properly escaped
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Files Addon for Event Espresso 4 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Files Addon for Event Espresso 4 Release Timeline

v1.2.1Current
v1.2
v1.0.9
v1.0.8
v1.0.7
v1.0.6
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Files Addon for Event Espresso 4 Code Analysis

Dangerous Functions
0
Raw SQL Queries
6
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared6 total queries

Output Escaping

0% escaped1 total outputs
Attack Surface
2 unprotected

Files Addon for Event Espresso 4 Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_ssa_upload_fileeea-file.php:77
noprivwp_ajax_ssa_upload_fileeea-file.php:78
WordPress Hooks 13
actionactivated_plugineea-file.php:27
actionadmin_noticeseea-file.php:40
actionAHEE__EE_System__load_espresso_addonseea-file.php:43
actionadmin_noticeseea-file.php:51
actioniniteea-file.php:54
filterupload_direea-file.php:108
actionadmin_headeea-file.php:167
actionadmin_enqueue_scriptsEE_File.class.php:33
actionAHEE__Extend_Registration_Form_Admin_Page___redirect_after_action__before_redirect_modification_insert_questionEE_File.class.php:58
actionAHEE__Extend_Registration_Form_Admin_Page___redirect_after_action__before_redirect_modification_update_questionEE_File.class.php:60
filterFHEE__EEM_Question__construct__allowed_question_typesssa_run_filters.php:2
filterFHEE__EE_SPCO_Reg_Step_Attendee_Information___generate_question_input__defaultssa_run_filters.php:8
filterFHEE__EEH_Form_Fields__input_htmlssa_run_filters.php:17
Maintenance & Trust

Files Addon for Event Espresso 4 Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedApr 28, 2024
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings3
Active installs40
Developer Profile

Files Addon for Event Espresso 4 Developer Profile

wordgeniee

1 plugin · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Files Addon for Event Espresso 4

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/files-addon-for-event-espresso-4/css/admin-screen.css/wp-content/plugins/files-addon-for-event-espresso-4/js/admin-js.js
Script Paths
js/admin-js.js
Version Parameters
files-addon-for-event-espresso-4/css/admin-screen.css?ver=files-addon-for-event-espresso-4/js/admin-js.js?ver=

HTML / DOM Fingerprints

JS Globals
ssa_var_ds
FAQ

Frequently Asked Questions about Files Addon for Event Espresso 4