
Events: Calendar, Boxes, and List Security & Risk Analysis
wordpress.org/plugins/fsdpe-eventsA simple and powerful events manager plugin with multiple views: calendar, boxes, and list.
Is Events: Calendar, Boxes, and List Safe to Use in 2026?
Generally Safe
Score 100/100Events: Calendar, Boxes, and List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "fsdpe-events" v1.1.3 plugin exhibits a generally good security posture with notable strengths. All SQL queries utilize prepared statements, and all output is properly escaped, significantly mitigating risks of SQL injection and cross-site scripting (XSS). The plugin also has no known vulnerabilities in its history and performs no external HTTP requests or file operations, further enhancing its security. However, there are several areas of concern regarding the attack surface. Three out of six total entry points, specifically three REST API routes, lack permission callbacks, meaning they are accessible without any authentication or authorization checks. Additionally, the use of the `unserialize` function, a known dangerous function, presents a potential risk if the data being unserialized is not sufficiently validated and sanitized, which is not explicitly addressed in the provided static analysis. While the plugin includes nonce checks and capability checks, their limited application to only two entry points leaves other potential vectors exposed.
Key Concerns
- REST API routes without permission callbacks
- Use of dangerous function: unserialize
- AJAX handlers without authentication checks
Events: Calendar, Boxes, and List Security Vulnerabilities
Events: Calendar, Boxes, and List Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Events: Calendar, Boxes, and List Attack Surface
AJAX Handlers 1
REST API Routes 3
Shortcodes 2
WordPress Hooks 16
Maintenance & Trust
Events: Calendar, Boxes, and List Maintenance & Trust
Maintenance Signals
Community Trust
Events: Calendar, Boxes, and List Alternatives
The Events Calendar
the-events-calendar
The Events Calendar: #1 calendar plugin for WordPress. Create/manage events (virtual too!) on your site with the free plugin.
Events Calendar for GeoDirectory
events-for-geodirectory
Events Calendar add-on for GeoDirectory allows to extend your GeoDirectory powered website with a versatile event manager.
Events Calendar Plus
events-calendar-plus
Display a beautiful events calendar with customizable views, coloring, filtering, date formats, images, and optimized for mobile on your own website.
Pretty Grid – WordPress Images Gallery, Slider, and Carousel Plugin
pretty-grid
Pretty Grid is a flexible plugin that make you display social media content in WordPress.
Crowdcue
crowdcue
Crowdcue is the unofficial OccasionGenius WordPress plugin allows you to easily output a beautiful and simple events page without any coding using the …
Events: Calendar, Boxes, and List Developer Profile
4 plugins · 2K total installs
How We Detect Events: Calendar, Boxes, and List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fsdpe-events/build/index.js/wp-content/plugins/fsdpe-events/build/index.css/wp-content/plugins/fsdpe-events/build/index.jsfsdpe-events/build/index.js?ver=fsdpe-events/build/index.css?ver=HTML / DOM Fingerprints
fsdpe-events-settingsfsdpeEventsSettings/wp-json/fsdpe-events/v1/custom-posts