
Kalendář / Calendar Security & Risk Analysis
wordpress.org/plugins/kalendar-czCZ
Is Kalendář / Calendar Safe to Use in 2026?
Generally Safe
Score 85/100Kalendář / Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the 'kalendar-cz' v2.0 plugin reveals a concerning security posture, despite the absence of identified vulnerabilities in its history. The plugin exhibits several poor coding practices that significantly increase its risk profile. Notably, 100% of its SQL queries are executed without prepared statements, a critical oversight that exposes the plugin to SQL injection vulnerabilities. Furthermore, 100% of its outputs are not properly escaped, creating a high risk of Cross-Site Scripting (XSS) attacks. The presence of file operations without explicit mention of sanitization or authorization checks also warrants caution.
The plugin's attack surface appears minimal with zero identified entry points (AJAX handlers, REST API routes, shortcodes, cron events). However, this is overshadowed by the poor code quality observed in SQL execution and output handling. The complete lack of vulnerability history, while seemingly positive, could also indicate a lack of rigorous security auditing or a limited adoption, rather than a true absence of flaws. The plugin's strengths lie in its seemingly small attack surface and lack of external HTTP requests or bundled libraries. However, the significant weaknesses in secure coding practices for database interaction and output sanitization present substantial and immediate risks to any WordPress site using this plugin.
Key Concerns
- 100% of SQL queries lack prepared statements
- 100% of outputs are not properly escaped
- File operations present without explicit security checks
- No nonce checks implemented
- No capability checks implemented
Kalendář / Calendar Security Vulnerabilities
Kalendář / Calendar Code Analysis
SQL Query Safety
Output Escaping
Kalendář / Calendar Attack Surface
WordPress Hooks 5
Maintenance & Trust
Kalendář / Calendar Maintenance & Trust
Maintenance Signals
Community Trust
Kalendář / Calendar Alternatives
Kalendarium CZ
kalendarium-cz
Shows actual date and the czech name days in the sidebar
CPT Calender Widget for WordPress
cpt-calender-widget
Create Custom Post and and select CPT from dropdown.
ARCW Popover Addon
arcw-popover-addon
Popover Addon for Archives Calendar Widget
LCS Fast Calendar Widget for Events Manager
lcs-em-widget-calendar
This plugin adds a fast sidebar calendar widget to replace the one that comes with Events Manager.
Custom Sidebars – Dynamic Sidebar Classic Widget Area Manager
custom-sidebars
Flexible sidebars for custom classic widget configurations on any page or post. Create custom sidebars with ease!
Kalendář / Calendar Developer Profile
3 plugins · 220 total installs
How We Detect Kalendář / Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.