Kalendarium CZ Security & Risk Analysis

wordpress.org/plugins/kalendarium-cz

Shows actual date and the czech name days in the sidebar

100 active installs v1.2.1 PHP + WP 2.5+ Updated Jun 18, 2010
calendarczechsidebarwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Kalendarium CZ Safe to Use in 2026?

Generally Safe

Score 85/100

Kalendarium CZ has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The Kalendarium-CZ plugin version 1.2.1 exhibits a mixed security posture. On one hand, the absence of known CVEs, raw SQL queries, and external HTTP requests is a positive sign. The static analysis also reveals no dangerous functions or file operations, indicating a generally well-written codebase in these areas. However, a significant concern arises from the complete lack of output escaping. With 6 total outputs and 0% properly escaped, this opens the door to cross-site scripting (XSS) vulnerabilities where user-supplied data, if not handled carefully by the application, could be rendered directly in the browser, leading to malicious script execution.

Furthermore, the plugin demonstrates no nonce checks or capability checks. While the attack surface appears to be zero based on the provided entry points, this lack of authorization and validation mechanisms is a risky practice. If any new entry points were introduced in future versions or if the analysis is incomplete, these omissions could be easily exploited. The vulnerability history is currently clean, which is good, but the lack of basic security checks like output escaping and authorization means that even a single development oversight could lead to a critical vulnerability. The plugin's strengths lie in its avoidance of common vulnerabilities like SQL injection and external request risks, but its weakness in output sanitization and authorization represents a substantial risk that should be addressed.

Key Concerns

  • All outputs unescaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Kalendarium CZ Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Kalendarium CZ Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Attack Surface

Kalendarium CZ Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionplugins_loadedkalendarium-cz.php:134
Maintenance & Trust

Kalendarium CZ Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedJun 18, 2010
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

Kalendarium CZ Developer Profile

svasek

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Kalendarium CZ

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
today
Shortcode Output
<div id="today"> <h6></h6></div>
FAQ

Frequently Asked Questions about Kalendarium CZ