GroupCal – Calendar for Businesses & Communities Security & Risk Analysis

wordpress.org/plugins/groupcal-events-calendar

GroupCal, #1 shared calendar platform worldwide. Display calendars on your site for free, and sync them with your audience's mobile calendar app.

10 active installs v1.3 PHP 7.4+ WP 5.8+ Updated Mar 27, 2025
bookingcalendarcommunityeventsmobile-calendar
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is GroupCal – Calendar for Businesses & Communities Safe to Use in 2026?

Generally Safe

Score 92/100

GroupCal – Calendar for Businesses & Communities has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'groupcal-events-calendar' v1.3 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and the complete output escaping are excellent security practices. Furthermore, the plugin demonstrates no file operations or external HTTP requests, which significantly reduces potential attack vectors. The limited attack surface, consisting of a single shortcode with no apparent direct vulnerabilities detected in the code signals and taint analysis, is also a positive indicator.

The plugin's vulnerability history is spotless, with no known CVEs, indicating a consistent track record of security. This, combined with the clean static analysis, suggests the developers have a good understanding of secure coding principles for WordPress. The lack of critical or high severity taint flows, along with the complete absence of nonce and capability checks in the analyzed entry points, implies that the current entry points might be inherently safe or that the analysis scope was limited. However, the lack of nonce and capability checks on the shortcode, which is the sole entry point, presents a potential concern that warrants further investigation if this shortcode interacts with sensitive data or performs actions that require authorization.

In conclusion, 'groupcal-events-calendar' v1.3 appears to be a well-developed and secure plugin, with the developers adhering to many best practices. The primary area for potential improvement or further scrutiny lies in the authorization mechanisms for its sole entry point, the shortcode. While no vulnerabilities are currently apparent, ensuring robust permission checks for this element would further solidify its security.

Key Concerns

  • Missing capability checks on shortcode
  • Missing nonce checks on shortcode
Vulnerabilities
None known

GroupCal – Calendar for Businesses & Communities Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

GroupCal – Calendar for Businesses & Communities Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped8 total outputs
Attack Surface

GroupCal – Calendar for Businesses & Communities Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[groupcal_iframe] groupcal-events-calendar.php:41
WordPress Hooks 3
actioninitgroupcal-events-calendar.php:56
actionadmin_menugroupcal-events-calendar.php:104
actionadmin_enqueue_scriptsgroupcal-events-calendar.php:141
Maintenance & Trust

GroupCal – Calendar for Businesses & Communities Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 27, 2025
PHP min version7.4
Downloads691

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

GroupCal – Calendar for Businesses & Communities Developer Profile

groupcal

1 plugin · 10 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GroupCal – Calendar for Businesses & Communities

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/groupcal-events-calendar/block.js
Script Paths
/wp-content/plugins/groupcal-events-calendar/block.js
Version Parameters
groupcal-events-calendar/block.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-block="groupcal/iframe-block"
JS Globals
wp.blockswp.elementwp.editor
Shortcode Output
<div style=" max-width: vw; height: vh; position: relative; margin: auto;"><iframe id="playersss" src="" style="width: 100%; height: 100%; border: none; display: block;" frameborder="0"></iframe></div>
FAQ

Frequently Asked Questions about GroupCal – Calendar for Businesses & Communities