
iCal Feeds Security & Risk Analysis
wordpress.org/plugins/ical-feedsGenerate a customizable iCal feed of your present and future blog posts.
Is iCal Feeds Safe to Use in 2026?
Use With Caution
Score 64/100iCal Feeds has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "ical-feeds" v1.5.3 plugin exhibits a mixed security posture. While the static analysis shows no directly exposed attack surface (AJAX handlers, REST API, shortcodes, cron events) without authentication, and all SQL queries utilize prepared statements, significant concerns arise from the output escaping and the vulnerability history. The fact that 0% of the 45 identified outputs are properly escaped is a critical weakness, strongly indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. This is further corroborated by the vulnerability history, which lists a past medium severity XSS vulnerability. The single identified flow with unsanitized paths in the taint analysis, though not rated critical or high in the static analysis, combined with the unescaped output, paints a concerning picture for user-supplied data that might be rendered. The plugin has one unpatched medium-severity CVE, which is a direct and significant risk that needs immediate attention. Despite the absence of obvious entry points and secure SQL practices, the critical lack of output escaping and the outstanding vulnerability demand caution.
Key Concerns
- Unpatched medium severity CVE
- No properly escaped output found
- Flow with unsanitized paths detected
iCal Feeds Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
iCal Feeds <= 1.5.3 - Reflected Cross-Site Scripting
iCal Feeds Release Timeline
iCal Feeds Code Analysis
Output Escaping
Data Flow Analysis
iCal Feeds Attack Surface
WordPress Hooks 3
Maintenance & Trust
iCal Feeds Maintenance & Trust
Maintenance Signals
Community Trust
iCal Feeds Alternatives
Smash Balloon Social Post Feed – Simple Social Feeds for WordPress
custom-facebook-feed
Formerly "Custom Facebook Feed". Display completely customizable Facebook feeds of a Facebook page. Supports Facebook oEmbeds.
Easy Social Feed – Social Photos Gallery and Post Feed for WordPress
easy-facebook-likebox
Display Instagram, Facebook & YouTube feeds with photos, videos, reels, events & galleries. Fast, responsive & easy to set up.
ICS Calendar
ics-calendar
Add the calendar you already use to Any WordPress site! Google Calendar, Microsoft 365, iCloud and more… no API keys or complicated setup required.
WP Missed Schedule Posts
wp-missed-schedule-posts
Auto publish future/scheduled posts missed by WordPress cron
Hierarchical HTML Sitemap
hierarchical-html-sitemap
A lightweight and simple HTML sitemap for your WordPress blog.
iCal Feeds Developer Profile
3 plugins · 310 total installs
How We Detect iCal Feeds
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
<a href="" target="_blank"></a> — Public iCal feed