GCal Events List Security & Risk Analysis

wordpress.org/plugins/gcal-events-list

GCal Events List retrieves future events from a public Google Calendar and shows data in a widget.

10 active installs v2.1 PHP + WP 4.8+ Updated Jul 26, 2017
calendareventsgooglewidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GCal Events List Safe to Use in 2026?

Generally Safe

Score 85/100

GCal Events List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'gcal-events-list' plugin version 2.1 exhibits a mixed security posture. On one hand, the plugin demonstrates good practices by having no identified dangerous functions, all SQL queries utilizing prepared statements, and no file operations or bundled libraries. The absence of known vulnerabilities in its history is also a positive indicator. However, significant concerns arise from the static analysis. The plugin has a complete lack of output escaping, meaning all 27 identified output points are potentially vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the absence of nonce checks and capability checks on any entry points, combined with no recorded vulnerabilities historically, suggests a potentially large, undiscovered attack surface that is not being adequately protected. The presence of an external HTTP request without clear sanitization or authentication context also warrants attention. While the plugin has a clean vulnerability history and avoids common pitfalls like raw SQL, the unescaped output and lack of robust access controls present substantial risks that could be exploited if an attacker can trigger these output points.

Key Concerns

  • 0% output escaping
  • 0 nonce checks
  • 0 capability checks
  • 1 external HTTP request without context
Vulnerabilities
None known

GCal Events List Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

GCal Events List Release Timeline

v2.0
v0.1
Code Analysis
Analyzed Mar 17, 2026

GCal Events List Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
27
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped27 total outputs
Attack Surface

GCal Events List Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initgcal_events_list.php:178
Maintenance & Trust

GCal Events List Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedJul 26, 2017
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

GCal Events List Developer Profile

veleno

2 plugins · 40 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GCal Events List

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Data Attributes
widget_gcal-events-list
FAQ

Frequently Asked Questions about GCal Events List