
GCal Events List Security & Risk Analysis
wordpress.org/plugins/gcal-events-listGCal Events List retrieves future events from a public Google Calendar and shows data in a widget.
Is GCal Events List Safe to Use in 2026?
Generally Safe
Score 85/100GCal Events List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'gcal-events-list' plugin version 2.1 exhibits a mixed security posture. On one hand, the plugin demonstrates good practices by having no identified dangerous functions, all SQL queries utilizing prepared statements, and no file operations or bundled libraries. The absence of known vulnerabilities in its history is also a positive indicator. However, significant concerns arise from the static analysis. The plugin has a complete lack of output escaping, meaning all 27 identified output points are potentially vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the absence of nonce checks and capability checks on any entry points, combined with no recorded vulnerabilities historically, suggests a potentially large, undiscovered attack surface that is not being adequately protected. The presence of an external HTTP request without clear sanitization or authentication context also warrants attention. While the plugin has a clean vulnerability history and avoids common pitfalls like raw SQL, the unescaped output and lack of robust access controls present substantial risks that could be exploited if an attacker can trigger these output points.
Key Concerns
- 0% output escaping
- 0 nonce checks
- 0 capability checks
- 1 external HTTP request without context
GCal Events List Security Vulnerabilities
GCal Events List Release Timeline
GCal Events List Code Analysis
Output Escaping
GCal Events List Attack Surface
WordPress Hooks 1
Maintenance & Trust
GCal Events List Maintenance & Trust
Maintenance Signals
Community Trust
GCal Events List Alternatives
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
Events Widgets For Elementor And The Events Calendar
events-widgets-for-elementor-and-the-events-calendar
The Events Calendar Elementor widgets help you manage and display an upcoming events list with date, time, venue and event ticket booking details.
ICS Calendar
ics-calendar
Add the calendar you already use to Any WordPress site! Google Calendar, Microsoft 365, iCloud and more… no API keys or complicated setup required.
Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar
booking-manager
Showing events listing from .ics feeds or sync bookings from different sources to your website
Events Calendar for Google
events-calendar-for-google
Events Calendar for Google implements google calender to your wordpress website using different style and layouts. Get connected to your audience usin …
GCal Events List Developer Profile
2 plugins · 40 total installs
How We Detect GCal Events List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
widget_gcal-events-list