Import Eventbrite Events Security & Risk Analysis

wordpress.org/plugins/import-eventbrite-events

Import Eventbrite Events into WordPress website and/or Event Calendar. Nice Display with shortcode & Event widget.

3K active installs v1.8.0 PHP 5.3+ WP 4.0+ Updated Feb 20, 2026
calendareventbriteeventbrite-eventeventsimport
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 13, 2024
Safety Verdict

Is Import Eventbrite Events Safe to Use in 2026?

Generally Safe

Score 99/100

Import Eventbrite Events has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 13, 2024Updated 1mo ago
Risk Assessment

The "import-eventbrite-events" plugin v1.8.0 exhibits a mixed security posture. On the positive side, it demonstrates strong practices in SQL query preparation (89%) and output escaping (97%), significantly reducing the risk of common injection and XSS vulnerabilities in the majority of its operations. The plugin also includes a reasonable number of nonce and capability checks, indicating an awareness of security best practices. However, there are notable areas of concern. The presence of three AJAX handlers without authentication checks presents a significant attack surface that could be exploited by unauthenticated users. Furthermore, the use of the `unserialize` function, while not explicitly showing a critical taint flow, is a known risk vector that requires careful sanitization of the data being unserialized to prevent deserialization vulnerabilities.

The plugin's vulnerability history, with one medium-severity CVE related to Cross-Site Scripting, reinforces the importance of input sanitization and output encoding, even with the high percentage of escaped outputs observed. While there are no currently unpatched vulnerabilities, the past occurrence of XSS suggests that careful review of all user-controlled input is crucial. The taint analysis showed no critical or high-severity unsanitized paths, which is a positive indicator for the immediate execution environment. Overall, the plugin has strengths in its general coding practices but requires immediate attention to its unprotected AJAX endpoints and careful review of the `unserialize` usage to mitigate potential risks.

Key Concerns

  • 3 AJAX handlers without auth checks
  • Dangerous function: unserialize
  • 1 medium CVE in vulnerability history
Vulnerabilities
1

Import Eventbrite Events Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2024-12422medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Import Eventbrite Events <= 1.7.4 - Reflected Cross-Site Scripting

Dec 13, 2024 Patched in 1.7.5 (1d)
Code Analysis
Analyzed Mar 16, 2026

Import Eventbrite Events Code Analysis

Dangerous Functions
1
Raw SQL Queries
12
99 prepared
Unescaped Output
28
786 escaped
Nonce Checks
16
Capability Checks
3
File Operations
1
External Requests
9
Bundled Libraries
0

Dangerous Functions Found

unserialize$schedule = unserialize( $data->schedule ); // phpcs:ignore WordPress.PHP.DiscouragedPHPFunctions.seincludes\iee-action-scheduler\action-scheduler\classes\data-stores\ActionScheduler_DBStore.php:397

SQL Query Safety

89% prepared111 total queries

Output Escaping

97% escaped814 total outputs
Data Flows
5 unsanitized

Data Flow Analysis

11 flows5 with unsanitized paths
admin_page (includes\class-import-eventbrite-events-admin.php:212)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
3 unprotected

Import Eventbrite Events Attack Surface

Entry Points4
Unprotected3

AJAX Handlers 3

authwp_ajax_iee_load_paged_eventsincludes\class-import-eventbrite-events-ajax.php:25
noprivwp_ajax_iee_load_paged_eventsincludes\class-import-eventbrite-events-ajax.php:26
authwp_ajax_iee_render_terms_by_pluginincludes\class-import-eventbrite-events-common.php:29

Shortcodes 1

[eventbrite_events] includes\class-import-eventbrite-events-cpt.php:61
WordPress Hooks 128
actioninitblocks\eventbrite-events\index.php:70
actionplugins_loadedimport-eventbrite-events.php:59
actionwp_enqueue_scriptsimport-eventbrite-events.php:60
actionwp_enqueue_scriptsimport-eventbrite-events.php:61
actionadmin_footerincludes\class-iee-plugin-deactivation.php:41
actioninitincludes\class-import-eventbrite-events-admin.php:41
actioninitincludes\class-import-eventbrite-events-admin.php:42
actionadmin_initincludes\class-import-eventbrite-events-admin.php:43
actioniee_delete_past_events_cronincludes\class-import-eventbrite-events-admin.php:44
actionadmin_initincludes\class-import-eventbrite-events-admin.php:45
actionadmin_initincludes\class-import-eventbrite-events-admin.php:46
actionadmin_menuincludes\class-import-eventbrite-events-admin.php:47
filtersubmenu_fileincludes\class-import-eventbrite-events-admin.php:48
actionadmin_enqueue_scriptsincludes\class-import-eventbrite-events-admin.php:49
actionadmin_enqueue_scriptsincludes\class-import-eventbrite-events-admin.php:50
actionadmin_noticesincludes\class-import-eventbrite-events-admin.php:51
actioniee_display_all_noticeincludes\class-import-eventbrite-events-admin.php:52
filteradmin_footer_textincludes\class-import-eventbrite-events-admin.php:53
actionadmin_action_iee_view_import_historyincludes\class-import-eventbrite-events-admin.php:54
actionadmin_initincludes\class-import-eventbrite-events-admin.php:55
actioninitincludes\class-import-eventbrite-events-admin.php:56
actioninitincludes\class-import-eventbrite-events-common.php:25
actionadmin_initincludes\class-import-eventbrite-events-common.php:26
actionadmin_initincludes\class-import-eventbrite-events-common.php:27
actionadmin_initincludes\class-import-eventbrite-events-common.php:28
actiontribe_events_single_event_after_the_metaincludes\class-import-eventbrite-events-common.php:30
filterthe_contentincludes\class-import-eventbrite-events-common.php:31
actionep_after_single_event_contantincludes\class-import-eventbrite-events-common.php:32
filtermc_event_contentincludes\class-import-eventbrite-events-common.php:33
actioniee_render_pro_noticeincludes\class-import-eventbrite-events-common.php:34
actionadmin_initincludes\class-import-eventbrite-events-common.php:35
actionadmin_initincludes\class-import-eventbrite-events-common.php:36
actioninitincludes\class-import-eventbrite-events-cpt.php:52
actioninitincludes\class-import-eventbrite-events-cpt.php:53
actionadd_meta_boxesincludes\class-import-eventbrite-events-cpt.php:54
actionsave_postincludes\class-import-eventbrite-events-cpt.php:55
filtermanage_eventbrite_events_posts_columnsincludes\class-import-eventbrite-events-cpt.php:57
actionmanage_posts_custom_columnincludes\class-import-eventbrite-events-cpt.php:58
filterthe_contentincludes\class-import-eventbrite-events-cpt.php:60
actionadmin_initincludes\class-import-eventbrite-events-manage-import.php:24
actionadmin_initincludes\class-import-eventbrite-events-manage-import.php:25
actionplugins_loadedincludes\iee-action-scheduler\action-scheduler\action-scheduler.php:36
actionplugins_loadedincludes\iee-action-scheduler\action-scheduler\action-scheduler.php:39
actioninitincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler.php:196
actioninitincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler.php:197
actioninitincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler.php:198
actioninitincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler.php:199
actioninitincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler.php:200
actioninitincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler.php:202
actionaction_scheduler/migration_completeincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler.php:261
actionaction_scheduler_canceled_actionincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:67
actionaction_scheduler_begin_executeincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:68
actionaction_scheduler_after_executeincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:69
actionaction_scheduler_failed_executionincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:70
actionaction_scheduler_failed_actionincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:71
actionaction_scheduler_unexpected_shutdownincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:72
actionaction_scheduler_reset_actionincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:73
actionaction_scheduler_execution_ignoredincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:74
actionaction_scheduler_failed_fetch_actionincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:75
actionaction_scheduler_failed_to_schedule_next_instanceincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:76
actionaction_scheduler_bulk_cancel_actionsincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:77
actionaction_scheduler_stored_actionincludes\iee-action-scheduler\action-scheduler\classes\abstracts\ActionScheduler_Logger.php:84
actionwoocommerce_admin_status_content_action-schedulerincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_AdminView.php:56
actionwoocommerce_system_status_reportincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_AdminView.php:57
filterwoocommerce_admin_status_tabsincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_AdminView.php:58
actionadmin_menuincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_AdminView.php:61
actionadmin_noticesincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_AdminView.php:62
actioncurrent_screenincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_AdminView.php:63
filteraction_scheduler_store_classincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_DataController.php:190
filteraction_scheduler_logger_classincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_DataController.php:191
actiondeactivate_pluginincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_DataController.php:192
actionaction_scheduler/progress_tickincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_DataController.php:197
actionshutdownincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_FatalErrorMonitor.php:45
actionaction_scheduler_before_executeincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_FatalErrorMonitor.php:46
actionaction_scheduler_after_executeincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_FatalErrorMonitor.php:47
actionaction_scheduler_execution_ignoredincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_FatalErrorMonitor.php:48
actionaction_scheduler_failed_executionincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_FatalErrorMonitor.php:49
actionaction_scheduler/created_tableincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_ListTable.php:554
filtercron_schedulesincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_QueueRunner.php:72
actionshutdownincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_QueueRunner.php:95
actionaction_scheduler_initincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_RecurringActionScheduler.php:28
actionpre_get_commentsincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_WPCommentCleaner.php:44
actionwp_count_commentsincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_WPCommentCleaner.php:45
actioncomment_feed_whereincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_WPCommentCleaner.php:46
actionload-tools_page_action-schedulerincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_WPCommentCleaner.php:49
actionload-woocommerce_page_wc-statusincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_WPCommentCleaner.php:50
actionadmin_noticesincludes\iee-action-scheduler\action-scheduler\classes\ActionScheduler_WPCommentCleaner.php:109
actionaction_scheduler_deleted_actionincludes\iee-action-scheduler\action-scheduler\classes\data-stores\ActionScheduler_DBLogger.php:112
actionaction_scheduler/created_tableincludes\iee-action-scheduler\action-scheduler\classes\data-stores\ActionScheduler_HybridStore.php:75
filtercomments_clausesincludes\iee-action-scheduler\action-scheduler\classes\data-stores\ActionScheduler_wpCommentLogger.php:129
actionaction_scheduler_before_process_queueincludes\iee-action-scheduler\action-scheduler\classes\data-stores\ActionScheduler_wpCommentLogger.php:254
actionaction_scheduler_after_process_queueincludes\iee-action-scheduler\action-scheduler\classes\data-stores\ActionScheduler_wpCommentLogger.php:255
actionpre_get_commentsincludes\iee-action-scheduler\action-scheduler\classes\data-stores\ActionScheduler_wpCommentLogger.php:259
actionwp_count_commentsincludes\iee-action-scheduler\action-scheduler\classes\data-stores\ActionScheduler_wpCommentLogger.php:260
actioncomment_feed_whereincludes\iee-action-scheduler\action-scheduler\classes\data-stores\ActionScheduler_wpCommentLogger.php:261
actionwp_insert_commentincludes\iee-action-scheduler\action-scheduler\classes\data-stores\ActionScheduler_wpCommentLogger.php:264
actionwp_set_comment_statusincludes\iee-action-scheduler\action-scheduler\classes\data-stores\ActionScheduler_wpCommentLogger.php:265
filterwp_insert_post_dataincludes\iee-action-scheduler\action-scheduler\classes\data-stores\ActionScheduler_wpPostStore.php:81
filterpre_wp_unique_post_slugincludes\iee-action-scheduler\action-scheduler\classes\data-stores\ActionScheduler_wpPostStore.php:82
filterpre_wp_unique_post_slugincludes\iee-action-scheduler\action-scheduler\classes\data-stores\ActionScheduler_wpPostStore.php:518
filterwp_insert_post_dataincludes\iee-action-scheduler\action-scheduler\classes\data-stores\ActionScheduler_wpPostStore.php:1006
filterpre_wp_unique_post_slugincludes\iee-action-scheduler\action-scheduler\classes\data-stores\ActionScheduler_wpPostStore.php:1007
filteraction_scheduler_migration_dependencies_metincludes\iee-action-scheduler\action-scheduler\classes\data-stores\ActionScheduler_wpPostStore.php:1094
actionadmin_noticesincludes\iee-action-scheduler\action-scheduler\classes\migration\Controller.php:176
filteraction_scheduler_store_classincludes\iee-action-scheduler\action-scheduler\classes\migration\Controller.php:190
filteraction_scheduler_logger_classincludes\iee-action-scheduler\action-scheduler\classes\migration\Controller.php:191
actioninitincludes\iee-action-scheduler\action-scheduler\classes\migration\Controller.php:192
actionwp_loadedincludes\iee-action-scheduler\action-scheduler\classes\migration\Controller.php:193
actionload-tools_page_action-schedulerincludes\iee-action-scheduler\action-scheduler\classes\migration\Controller.php:196
actionload-woocommerce_page_wc-statusincludes\iee-action-scheduler\action-scheduler\classes\migration\Controller.php:197
actionaction_scheduler_before_schema_updateincludes\iee-action-scheduler\action-scheduler\classes\schema\ActionScheduler_LoggerSchema.php:35
actionaction_scheduler_before_schema_updateincludes\iee-action-scheduler\action-scheduler\classes\schema\ActionScheduler_StoreSchema.php:40
actionaction_scheduler_deleted_actionincludes\iee-action-scheduler\action-scheduler\classes\WP_CLI\Action\Delete_Command.php:40
actionaction_scheduler_execution_ignoredincludes\iee-action-scheduler\action-scheduler\classes\WP_CLI\Action\Run_Command.php:42
actionaction_scheduler_after_executeincludes\iee-action-scheduler\action-scheduler\classes\WP_CLI\Action\Run_Command.php:43
actionaction_scheduler_failed_executionincludes\iee-action-scheduler\action-scheduler\classes\WP_CLI\Action\Run_Command.php:44
actionaction_scheduler_failed_validationincludes\iee-action-scheduler\action-scheduler\classes\WP_CLI\Action\Run_Command.php:45
actionaction_scheduler_before_executeincludes\iee-action-scheduler\action-scheduler\classes\WP_CLI\ActionScheduler_WPCLI_QueueRunner.php:87
actionaction_scheduler_after_executeincludes\iee-action-scheduler\action-scheduler\classes\WP_CLI\ActionScheduler_WPCLI_QueueRunner.php:88
actionaction_scheduler_failed_executionincludes\iee-action-scheduler\action-scheduler\classes\WP_CLI\ActionScheduler_WPCLI_QueueRunner.php:89
actionaction_scheduler/migrate_action_dry_runincludes\iee-action-scheduler\action-scheduler\classes\WP_CLI\Migration_Command.php:137
actionaction_scheduler/no_action_to_migrateincludes\iee-action-scheduler\action-scheduler\classes\WP_CLI\Migration_Command.php:144
actionaction_scheduler/migrate_action_failedincludes\iee-action-scheduler\action-scheduler\classes\WP_CLI\Migration_Command.php:151
actionaction_scheduler/migrate_action_incompleteincludes\iee-action-scheduler\action-scheduler\classes\WP_CLI\Migration_Command.php:158
actionaction_scheduler/migrated_actionincludes\iee-action-scheduler\action-scheduler\classes\WP_CLI\Migration_Command.php:167
actionaction_scheduler/migration_batch_startingincludes\iee-action-scheduler\action-scheduler\classes\WP_CLI\Migration_Command.php:176
actionaction_scheduler/migration_batch_completeincludes\iee-action-scheduler\action-scheduler\classes\WP_CLI\Migration_Command.php:183
actioniee_process_image_downloadincludes\iee-action-scheduler\iee-image-init.php:13

Scheduled Events 3

iee_run_scheduled_import
iee_delete_past_events_cron
iee_run_scheduled_import
Maintenance & Trust

Import Eventbrite Events Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 20, 2026
PHP min version5.3
Downloads181K

Community Trust

Rating90/100
Number of ratings49
Active installs3K
Developer Profile

Import Eventbrite Events Developer Profile

Xylus Themes

13 plugins · 110K total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
105 days
View full developer profile
Detection Fingerprints

How We Detect Import Eventbrite Events

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/import-eventbrite-events/assets/css/style.css/wp-content/plugins/import-eventbrite-events/assets/js/script.js/wp-content/plugins/import-eventbrite-events/admin/css/admin-style.css/wp-content/plugins/import-eventbrite-events/admin/js/admin-script.js
Script Paths
/wp-content/plugins/import-eventbrite-events/assets/js/script.js/wp-content/plugins/import-eventbrite-events/admin/js/admin-script.js
Version Parameters
import-eventbrite-events/assets/css/style.css?ver=import-eventbrite-events/assets/js/script.js?ver=import-eventbrite-events/admin/css/admin-style.css?ver=import-eventbrite-events/admin/js/admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
import-eventbrite-events-admin-wrapiee-settings-formeventbrite-import-noticeimport-eventbrite-events-settings
HTML Comments
<!-- import-eventbrite-events main section start --><!-- import-eventbrite-events main section end --><!-- import-eventbrite-events settings form start --><!-- import-eventbrite-events settings form end -->+2 more
Data Attributes
data-plugin-name="Import Eventbrite Events"data-plugin-version="1.8.0"
JS Globals
iee_ajax_objectImportEventbriteEventsAdmin
REST Endpoints
/wp-json/import-eventbrite-events/v1/get-events/wp-json/import-eventbrite-events/v1/import-event
FAQ

Frequently Asked Questions about Import Eventbrite Events