Holiday class post calendar Security & Risk Analysis

wordpress.org/plugins/holiday-class-post-calendar

投稿カレンダーに日曜、土曜、祭日及び独自の休日などのスタイル設定するためのclassを付加します。

80 active installs v7.2 PHP 7.0+ WP 4.5+ Updated Dec 9, 2025
calendarclassholiday
94
A · Safe
CVEs total1
Unpatched0
Last CVENov 10, 2025
Safety Verdict

Is Holiday class post calendar Safe to Use in 2026?

Generally Safe

Score 94/100

Holiday class post calendar has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 10, 2025Updated 3mo ago
Risk Assessment

The static analysis of holiday-class-post-calendar v7.2 reveals a generally strong security posture in terms of coding practices. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and proper output escaping are all positive indicators. Furthermore, the plugin appears to have a very limited attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events exposed without authentication. Taint analysis also shows no concerning unsanitized flows. However, the plugin's history is marred by a critical vulnerability in the past, specifically related to code injection. While this vulnerability is reportedly patched, the presence of a past critical issue, especially one as severe as code injection, warrants caution. This historical event, combined with a complete lack of capability checks and nonce checks, suggests a potential for oversight in securing entry points that might exist beyond the analyzed static components, or perhaps in areas that were the source of the past critical vulnerability.

Key Concerns

  • Past critical vulnerability (code injection)
  • No nonce checks found
  • No capability checks found
Vulnerabilities
1

Holiday class post calendar Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Critical
1

1 total CVE

CVE-2025-12813critical · 9.8Improper Control of Generation of Code ('Code Injection')

Holiday class post calendar <= 7.1 - Unauthenticated Remote Code Execution via 'contents'

Nov 10, 2025 Patched in 7.2 (31d)
Code Analysis
Analyzed Mar 16, 2026

Holiday class post calendar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
0
153 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

100% escaped153 total outputs
Attack Surface

Holiday class post calendar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 10
actionwp_enqueue_scriptsholiday_class_post_calendar.php:177
actionwp_headholiday_class_post_calendar.php:183
actionwp_headholiday_class_post_calendar.php:188
actionadmin_head-post.phpholiday_class_post_calendar.php:190
actionadmin_head-widgets.phpholiday_class_post_calendar.php:191
actioninitholiday_class_post_calendar.php:195
filtersafe_style_cssholiday_class_post_calendar.php:198
actionadmin_initholiday_class_post_calendar.php:428
actionadmin_menuholiday_class_post_calendar.php:1235
filtergetarchives_whereholiday_class_post_calendar.php:1261
Maintenance & Trust

Holiday class post calendar Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 9, 2025
PHP min version7.0
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs80
Developer Profile

Holiday class post calendar Developer Profile

strix-bubol5

3 plugins · 290 total installs

83
trust score
Avg Security Score
93/100
Avg Patch Time
31 days
View full developer profile
Detection Fingerprints

How We Detect Holiday class post calendar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/holiday-class-post-calendar/hldycls_calendar.css/wp-content/plugins/holiday-class-post-calendar/hldycls_calendar.js/wp-content/plugins/holiday-class-post-calendar/hldycls_gb.js
Script Paths
wp-content/plugins/holiday-class-post-calendar/hldycls_calendar.jswp-content/plugins/holiday-class-post-calendar/hldycls_gb.js
Version Parameters
holiday-class-post-calendar/hldycls_calendar.css?ver=holiday-class-post-calendar/hldycls_calendar.js?ver=

HTML / DOM Fingerprints

CSS Classes
hldycls-pcldrhldycls-grid
HTML Comments
<!-- holiday class post calendar -->
Data Attributes
data-post
JS Globals
hldycls_pcldr_obj
Shortcode Output
[hldycls_pcldr]
FAQ

Frequently Asked Questions about Holiday class post calendar