GatherPress Security & Risk Analysis

wordpress.org/plugins/gatherpress

GatherPress is a flexible, community-powered event management plugin for WordPress.

50 active installs v0.33.3 PHP 7.4+ WP 6.7+ Updated Unknown
communityeventeventsmeetup
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GatherPress Safe to Use in 2026?

Generally Safe

Score 100/100

GatherPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The gatherpress plugin version 0.33.3 demonstrates a strong security posture based on the static analysis. The plugin effectively utilizes prepared statements for all SQL queries, employs robust output escaping, and implements a significant number of nonce and capability checks. The absence of dangerous functions, file operations, and external HTTP requests further contributes to its secure design. Crucially, there are no identified critical or high-severity taint flows, and the plugin has no recorded vulnerability history, indicating a well-maintained and secure codebase.

While the plugin shows excellent adherence to security best practices, the presence of one cron event is a minor point of consideration, as cron events can sometimes be leveraged for privilege escalation if not properly secured. However, without further information on the specific functionality of this cron event, it's difficult to assign a significant risk. Overall, gatherpress v0.33.3 appears to be a highly secure plugin with a minimal attack surface and a commendable lack of known vulnerabilities. The strengths in secure coding practices significantly outweigh any minor potential concerns.

Vulnerabilities
None known

GatherPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

GatherPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
11 prepared
Unescaped Output
9
433 escaped
Nonce Checks
3
Capability Checks
15
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared11 total queries

Output Escaping

98% escaped442 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<class-rsvp-list-table> (includes\core\classes\class-rsvp-list-table.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

GatherPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 118
filterpre_render_blockincludes\core\classes\blocks\class-event-query.php:64
filterquery_loop_block_query_varsincludes\core\classes\blocks\class-event-query.php:139
filterrender_blockincludes\core\classes\blocks\class-general-block.php:60
filterrender_blockincludes\core\classes\blocks\class-general-block.php:61
filterrender_block_core/buttonincludes\core\classes\blocks\class-general-block.php:62
filterrender_blockincludes\core\classes\blocks\class-rsvp-form.php:88
actionsave_postincludes\core\classes\blocks\class-rsvp-form.php:89
filterget_avatar_dataincludes\core\classes\blocks\class-rsvp-response.php:73
filterblock_type_metadataincludes\core\classes\blocks\class-rsvp-response.php:74
actionadmin_print_scriptsincludes\core\classes\class-assets.php:87
actionadmin_enqueue_scriptsincludes\core\classes\class-assets.php:88
actionenqueue_block_assetsincludes\core\classes\class-assets.php:89
actionenqueue_block_editor_assetsincludes\core\classes\class-assets.php:90
actionenqueue_block_editor_assetsincludes\core\classes\class-assets.php:91
actioninitincludes\core\classes\class-assets.php:92
actionwp_headincludes\core\classes\class-assets.php:93
actionadmin_footerincludes\core\classes\class-assets.php:95
filterrender_blockincludes\core\classes\class-assets.php:97
actioninitincludes\core\classes\class-block.php:62
actioninitincludes\core\classes\class-block.php:63
actioninitincludes\core\classes\class-block.php:65
filterhooked_block_typesincludes\core\classes\class-block.php:67
filterhooked_block_core/paragraphincludes\core\classes\class-block.php:68
actionpre_get_postsincludes\core\classes\class-event-query.php:63
filterposts_clausesincludes\core\classes\class-event-query.php:64
filterpre_optionincludes\core\classes\class-event-query.php:216
filterget_the_archive_titleincludes\core\classes\class-event-query.php:234
filterposts_clausesincludes\core\classes\class-event-query.php:248
filterposts_clausesincludes\core\classes\class-event-query.php:251
actionrest_api_initincludes\core\classes\class-event-rest-api.php:62
actiongatherpress_send_emailsincludes\core\classes\class-event-rest-api.php:63
actioninitincludes\core\classes\class-event-setup.php:59
actioninitincludes\core\classes\class-event-setup.php:60
actioninitincludes\core\classes\class-event-setup.php:61
actionparse_requestincludes\core\classes\class-event-setup.php:62
actiondelete_postincludes\core\classes\class-event-setup.php:63
actionwp_after_insert_postincludes\core\classes\class-event-setup.php:64
filterredirect_canonicalincludes\core\classes\class-event-setup.php:73
actionpre_get_postsincludes\core\classes\class-event-setup.php:88
actionpre_get_postsincludes\core\classes\class-event-setup.php:89
filterget_the_dateincludes\core\classes\class-event-setup.php:90
filterthe_timeincludes\core\classes\class-event-setup.php:91
filterdisplay_post_statesincludes\core\classes\class-event-setup.php:92
filterposts_join_pagedincludes\core\classes\class-event-setup.php:690
filterposts_groupbyincludes\core\classes\class-event-setup.php:691
filterposts_orderbyincludes\core\classes\class-event-setup.php:692
filterposts_join_pagedincludes\core\classes\class-event-setup.php:786
filterposts_orderbyincludes\core\classes\class-event-setup.php:787
actionexport_wpincludes\core\classes\class-export.php:65
actionthe_postincludes\core\classes\class-export.php:76
filterwxr_export_skip_postmetaincludes\core\classes\class-export.php:77
filtergatherpress_event_feed_excerptincludes\core\classes\class-feed.php:57
filtergatherpress_event_feed_contentincludes\core\classes\class-feed.php:58
filterthe_excerpt_rssincludes\core\classes\class-feed.php:61
filterthe_content_feedincludes\core\classes\class-feed.php:62
actionpre_get_postsincludes\core\classes\class-feed.php:65
filterpost_type_archive_feed_linkincludes\core\classes\class-feed.php:68
actiongatherpress_importincludes\core\classes\class-import.php:71
filteradd_post_metadataincludes\core\classes\class-import.php:114
actioninitincludes\core\classes\class-rsvp-form.php:60
filterallow_empty_commentincludes\core\classes\class-rsvp-form.php:112
filtercomments_openincludes\core\classes\class-rsvp-form.php:114
filterpreprocess_commentincludes\core\classes\class-rsvp-form.php:116
actioncomment_postincludes\core\classes\class-rsvp-form.php:121
filtercomment_duplicate_messageincludes\core\classes\class-rsvp-form.php:126
filtercomment_post_redirectincludes\core\classes\class-rsvp-form.php:131
filterpre_comment_approvedincludes\core\classes\class-rsvp-form.php:194
filtercomments_clausesincludes\core\classes\class-rsvp-list-table.php:287
actionpre_get_commentsincludes\core\classes\class-rsvp-query.php:73
filtercomments_clausesincludes\core\classes\class-rsvp-query.php:74
actionwp_insert_commentincludes\core\classes\class-rsvp-query.php:75
actionpre_get_commentsincludes\core\classes\class-rsvp-query.php:125
actioninitincludes\core\classes\class-rsvp-setup.php:79
actioninitincludes\core\classes\class-rsvp-setup.php:80
actionwp_after_insert_postincludes\core\classes\class-rsvp-setup.php:81
actionadmin_menuincludes\core\classes\class-rsvp-setup.php:82
filtercomment_notification_recipientsincludes\core\classes\class-rsvp-setup.php:83
filterparent_fileincludes\core\classes\class-rsvp-setup.php:91
filterget_comments_numberincludes\core\classes\class-rsvp-setup.php:92
filtercomment_textincludes\core\classes\class-rsvp-setup.php:93
filtersubmenu_fileincludes\core\classes\class-rsvp-setup.php:379
actioninitincludes\core\classes\class-settings.php:91
actionadmin_menuincludes\core\classes\class-settings.php:92
actionadmin_headincludes\core\classes\class-settings.php:93
actionadmin_initincludes\core\classes\class-settings.php:94
actiongatherpress_settings_sectionincludes\core\classes\class-settings.php:95
actiongatherpress_text_afterincludes\core\classes\class-settings.php:96
actiongatherpress_text_afterincludes\core\classes\class-settings.php:97
actionupdate_option_gatherpress_generalincludes\core\classes\class-settings.php:98
filtersubmenu_fileincludes\core\classes\class-settings.php:100
actionadmin_initincludes\core\classes\class-setup.php:90
actionadmin_initincludes\core\classes\class-setup.php:91
actionadmin_noticesincludes\core\classes\class-setup.php:92
actionnetwork_admin_noticesincludes\core\classes\class-setup.php:93
actionwp_initialize_siteincludes\core\classes\class-setup.php:94
actionsend_headersincludes\core\classes\class-setup.php:95
filterblock_categories_allincludes\core\classes\class-setup.php:97
filterwpmu_drop_tablesincludes\core\classes\class-setup.php:98
filterbody_classincludes\core\classes\class-setup.php:99
filteris_protected_metaincludes\core\classes\class-setup.php:100
actioninitincludes\core\classes\class-topic.php:60
actionshow_user_profileincludes\core\classes\class-user.php:72
actionedit_user_profileincludes\core\classes\class-user.php:73
actionpersonal_options_updateincludes\core\classes\class-user.php:74
actionedit_user_profile_updateincludes\core\classes\class-user.php:75
filtergatherpress_datetime_formatincludes\core\classes\class-user.php:77
filtergatherpress_timezoneincludes\core\classes\class-user.php:78
actioninitincludes\core\classes\class-venue.php:80
actioninitincludes\core\classes\class-venue.php:81
actioninitincludes\core\classes\class-venue.php:82
actionpost_updatedincludes\core\classes\class-venue.php:83
actiondelete_postincludes\core\classes\class-venue.php:84
actionadmin_initincludes\core\classes\settings\class-base.php:124
filtergatherpress_sub_pagesincludes\core\classes\settings\class-base.php:126
actiongatherpress_settings_sectionincludes\core\classes\settings\class-credits.php:45
actionadmin_noticesincludes\core\duplicate-check.php:17
actionadmin_noticesincludes\core\requirements-check.php:18
actionadmin_noticesincludes\core\requirements-check.php:46

Scheduled Events 1

gatherpress_send_emails
Maintenance & Trust

GatherPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

GatherPress Developer Profile

GatherPress

1 plugin · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GatherPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gatherpress/dist/blocks.style.build.css/wp-content/plugins/gatherpress/dist/rsvp-template.style.build.css/wp-content/plugins/gatherpress/dist/editor.js/wp-content/plugins/gatherpress/dist/blocks.build.js/wp-content/plugins/gatherpress/dist/rsvp-template.build.js
Script Paths
/wp-content/plugins/gatherpress/dist/editor.js/wp-content/plugins/gatherpress/dist/blocks.build.js/wp-content/plugins/gatherpress/dist/rsvp-template.build.js
Version Parameters
gatherpress/dist/blocks.style.build.css?ver=gatherpress/dist/rsvp-template.style.build.css?ver=gatherpress/dist/editor.js?ver=gatherpress/dist/blocks.build.js?ver=gatherpress/dist/rsvp-template.build.js?ver=

HTML / DOM Fingerprints

CSS Classes
wp-block-gatherpress-rsvp-template
Data Attributes
data-wp-interactive="gatherpress"data-wp-watch="callbacks.renderBlocks"data-blocks
JS Globals
wp.blocks.getBlockTypeswp.element.createElement
REST Endpoints
/wp-json/gatherpress/v1/
FAQ

Frequently Asked Questions about GatherPress