Kalendář / Calendar Security & Risk Analysis

wordpress.org/plugins/kalendar-cz

CZ

200 active installs v2.0 PHP + WP 2.5+ Updated May 13, 2015
calendarczechkalendarsidebarwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Kalendář / Calendar Safe to Use in 2026?

Generally Safe

Score 85/100

Kalendář / Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The static analysis of the 'kalendar-cz' v2.0 plugin reveals a concerning security posture, despite the absence of identified vulnerabilities in its history. The plugin exhibits several poor coding practices that significantly increase its risk profile. Notably, 100% of its SQL queries are executed without prepared statements, a critical oversight that exposes the plugin to SQL injection vulnerabilities. Furthermore, 100% of its outputs are not properly escaped, creating a high risk of Cross-Site Scripting (XSS) attacks. The presence of file operations without explicit mention of sanitization or authorization checks also warrants caution.

The plugin's attack surface appears minimal with zero identified entry points (AJAX handlers, REST API routes, shortcodes, cron events). However, this is overshadowed by the poor code quality observed in SQL execution and output handling. The complete lack of vulnerability history, while seemingly positive, could also indicate a lack of rigorous security auditing or a limited adoption, rather than a true absence of flaws. The plugin's strengths lie in its seemingly small attack surface and lack of external HTTP requests or bundled libraries. However, the significant weaknesses in secure coding practices for database interaction and output sanitization present substantial and immediate risks to any WordPress site using this plugin.

Key Concerns

  • 100% of SQL queries lack prepared statements
  • 100% of outputs are not properly escaped
  • File operations present without explicit security checks
  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Kalendář / Calendar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Kalendář / Calendar Code Analysis

Dangerous Functions
0
Raw SQL Queries
10
0 prepared
Unescaped Output
16
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
3
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared10 total queries

Output Escaping

0% escaped16 total outputs
Attack Surface

Kalendář / Calendar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionactivate_kalendar-cz/kalendar_cz.phpkalendar_cz.php:15
actiondeactivate_kalendar-cz/kalendar_cz.phpkalendar_cz.php:17
actionwp_dashboard_setupkalendar_cz.php:19
actionadmin_menukalendar_cz.php:21
actionplugins_loadedkalendar_cz.php:23
Maintenance & Trust

Kalendář / Calendar Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedMay 13, 2015
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings3
Active installs200
Developer Profile

Kalendář / Calendar Developer Profile

Webster.K

3 plugins · 220 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kalendář / Calendar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Kalendář / Calendar