
iCal for WP Calendar Security & Risk Analysis
wordpress.org/plugins/ical-for-wp-calendarAn extension for the Wordpress plugin WP Calendar, which generates iCal / RFC5545 / RFC2445 conform files.
Is iCal for WP Calendar Safe to Use in 2026?
Generally Safe
Score 85/100iCal for WP Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of ical-for-wp-calendar v1.5.1 reveals a mixed security posture. While the plugin demonstrates good practices by utilizing prepared statements for all SQL queries and having no recorded vulnerabilities (CVEs), several concerning signals emerge from the code analysis. The presence of the `create_function` function is a significant red flag, as it is deprecated and can be a vector for code injection if used with untrusted input. Furthermore, a very low percentage (17%) of output escaping indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. The lack of any identified attack surface points (AJAX handlers, REST API routes, shortcodes, cron events) is positive, as it limits direct entry points for attackers. However, the substantial amount of unescaped output and the use of `create_function` significantly outweigh these positives, posing a tangible risk to users. The absence of any historical vulnerabilities might suggest a lack of active exploitation or that past issues were minor, but it doesn't negate the current code risks.
Key Concerns
- Dangerous function create_function used
- Low output escaping percentage (17%)
- No capability checks found
- No nonce checks found
iCal for WP Calendar Security Vulnerabilities
iCal for WP Calendar Code Analysis
Dangerous Functions Found
Output Escaping
iCal for WP Calendar Attack Surface
WordPress Hooks 5
Maintenance & Trust
iCal for WP Calendar Maintenance & Trust
Maintenance Signals
Community Trust
iCal for WP Calendar Alternatives
The Events Calendar Outlook Import Fix
the-events-calendar-outlook-import-fix
Fix import of calendar events from The Events Calendar to Outlook.
ICS Calendar
ics-calendar
Add the calendar you already use to Any WordPress site! Google Calendar, Microsoft 365, iCloud and more… no API keys or complicated setup required.
iCal for Events Calendar
ical-for-events-calendar
Add an iCal feed to your site for the Events Calendar plugin
The Events Calendar PRO Alarm
the-events-calendar-pro-alarm
Add alarm/alert to iCal feed created from The Events Calendar PRO plugin.
WP Booking System – Booking Calendar
wp-booking-system
The booking calendar plugin for WordPress. Get easy online booking with this lightweight and powerful booking calendar.
iCal for WP Calendar Developer Profile
1 plugin · 30 total installs
How We Detect iCal for WP Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ical-for-wp-calendar/ical-wp-calendar.phpical-for-wp-calendar/ical-wp-calendar.php?ver=HTML / DOM Fingerprints
<!-- THIS IS THE BEGINNING OF THE IGNORE SECTION --><!-- THIS IS THE END OF THE IGNORE SECTION -->