Calendar Event Add-on WooCommerce Bookings Security & Risk Analysis

wordpress.org/plugins/gcal-event-addon-woocommerce-bookings

This plugin is used to send additional information about the customer when WooCommerce Bookings creates an event in Google Calendar.

100 active installs v1.4 PHP + WP 4.4+ Updated Jul 15, 2024
google-calendarwoo-commercewoocommercewoocommerce-bookings
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Calendar Event Add-on WooCommerce Bookings Safe to Use in 2026?

Generally Safe

Score 92/100

Calendar Event Add-on WooCommerce Bookings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The static analysis of gcal-event-addon-woocommerce-bookings v1.4 reveals a generally strong security posture, with no critical vulnerabilities identified in the attack surface, code signals, or taint analysis. The plugin exhibits excellent practices by avoiding dangerous functions, using prepared statements for all SQL queries, and reporting no external HTTP requests or file operations. Furthermore, the complete absence of known CVEs, both historically and currently, suggests a history of responsible development and patching.

However, a significant concern arises from the fact that 100% of the single output identified was not properly escaped. This represents a potential risk for cross-site scripting (XSS) vulnerabilities if user-supplied data is directly outputted without sanitization. While the attack surface is currently zero, indicating no immediate direct entry points for exploitation, this single unescaped output is a weakness that could be exploited if the plugin's functionality evolves or if an attacker finds a way to inject data into that output context. The lack of capability checks and nonce checks, while not directly linked to a found vulnerability in this version, could become a concern if new entry points are added in future updates without proper security controls.

In conclusion, the plugin demonstrates a commitment to secure coding practices, particularly in its database interactions and avoidance of known dangerous functions. The clean vulnerability history further bolsters confidence. The primary weakness lies in the unescaped output, which, although a single instance, warrants attention. Developers should prioritize addressing this to ensure robust protection against potential XSS attacks.

Key Concerns

  • Output not properly escaped
Vulnerabilities
None known

Calendar Event Add-on WooCommerce Bookings Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Calendar Event Add-on WooCommerce Bookings Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped1 total outputs
Attack Surface

Calendar Event Add-on WooCommerce Bookings Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionadmin_menuindex.php:40
actionadmin_initindex.php:41
filterwoocommerce_bookings_gcalendar_syncindex.php:42
actionplugins_loadedindex.php:43
Maintenance & Trust

Calendar Event Add-on WooCommerce Bookings Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedJul 15, 2024
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

Calendar Event Add-on WooCommerce Bookings Developer Profile

Rajesh Kaswala

1 plugin · 100 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Calendar Event Add-on WooCommerce Bookings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
gcaleventwcb
Data Attributes
name="gcaleventwcb_event_description_additionals"id="gcaleventwcb_event_description_additionals"
FAQ

Frequently Asked Questions about Calendar Event Add-on WooCommerce Bookings