
Full Calendar Js Security & Risk Analysis
wordpress.org/plugins/full-calendar-jsDisplay multiple Calendar XML feeds into a jquery calendar. Works with Google Calendar and others.
Is Full Calendar Js Safe to Use in 2026?
Generally Safe
Score 85/100Full Calendar Js has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "full-calendar-js" v1.6 plugin exhibits a mixed security posture. On the positive side, the static analysis reveals a small attack surface with no unprotected entry points, no dangerous functions, and all SQL queries utilizing prepared statements. There are also no recorded vulnerabilities (CVEs) for this plugin, suggesting a relatively stable history. However, a significant concern arises from the complete lack of output escaping. With 22 total outputs and 0% properly escaped, this opens the door to potential cross-site scripting (XSS) vulnerabilities, where malicious code could be injected into the frontend through user-supplied data displayed by the plugin.
The absence of taint analysis results and the low number of entry points (solely a shortcode) limit the ability to identify complex injection or path traversal vulnerabilities. The lack of nonce checks and capability checks on the identified shortcode, while not explicitly flagged as a risk due to the lack of dynamic analysis, could become a concern if the shortcode handles user-provided data in a sensitive manner. Overall, while the plugin demonstrates good practices in database interaction and has a clean vulnerability history, the critical deficiency in output sanitization presents a notable risk.
Key Concerns
- 0% output escaping
- No capability checks on shortcode
- No nonce checks on shortcode
Full Calendar Js Security Vulnerabilities
Full Calendar Js Code Analysis
Output Escaping
Full Calendar Js Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Full Calendar Js Maintenance & Trust
Maintenance Signals
Community Trust
Full Calendar Js Alternatives
Pretty Google Calendar
pretty-google-calendar
Embedded Google Calendars that don't suck.
FullCalendar
fullcalendar
Display and customize one or many Google calendars. A non-official WordPress plugin for the (https://fullcalendar.io/) Open Source project.
TheRich WP Fullcalendar
therich-wp-fullcalendar
TheRich WP Fullcalendar helps you to add events and show thoes events in fullcalendar.
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
all-in-one-seo-pack
AIOSEO is the most powerful WordPress SEO plugin. Improve SEO rankings and traffic with comprehensive SEO tools and smart AI SEO optimizations!
Custom Fonts – Host Your Fonts Locally
custom-fonts
Custom Fonts is a powerful WordPress plugin that allows you to upload your own custom fonts or choose from a vast collection of Google Fonts, all host …
Full Calendar Js Developer Profile
1 plugin · 30 total installs
How We Detect Full Calendar Js
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/full-calendar-js/js/fullcalendar-1.5.4/fullcalendar/fullcalendar.css/wp-content/plugins/full-calendar-js/js/fullcalendar-1.5.4/fullcalendar/fullcalendar.js/wp-content/plugins/full-calendar-js/js/fullcalendar-1.5.4/fullcalendar/gcal.js/wp-content/plugins/full-calendar-js/js/fullcalendar-1.5.4/fullcalendar/fullcalendaragendamod.js/wp-content/plugins/full-calendar-js/js/fullcalendar-1.5.4/fullcalendar/fullcalendaroriginal.js/wp-content/plugins/full-calendar-js/js/fullcalendar-1.5.4/fullcalendar/moment.jsjs/fullcalendar-1.5.4/fullcalendar/fullcalendar.cssjs/fullcalendar-1.5.4/fullcalendar/fullcalendar.jsjs/fullcalendar-1.5.4/fullcalendar/gcal.jsjs/fullcalendar-1.5.4/fullcalendar/fullcalendaragendamod.jsjs/fullcalendar-1.5.4/fullcalendar/fullcalendaroriginal.jsjs/fullcalendar-1.5.4/fullcalendar/moment.jsHTML / DOM Fingerprints
gcal-event