
Kalendarium CZ Security & Risk Analysis
wordpress.org/plugins/kalendarium-czShows actual date and the czech name days in the sidebar
Is Kalendarium CZ Safe to Use in 2026?
Generally Safe
Score 85/100Kalendarium CZ has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Kalendarium-CZ plugin version 1.2.1 exhibits a mixed security posture. On one hand, the absence of known CVEs, raw SQL queries, and external HTTP requests is a positive sign. The static analysis also reveals no dangerous functions or file operations, indicating a generally well-written codebase in these areas. However, a significant concern arises from the complete lack of output escaping. With 6 total outputs and 0% properly escaped, this opens the door to cross-site scripting (XSS) vulnerabilities where user-supplied data, if not handled carefully by the application, could be rendered directly in the browser, leading to malicious script execution.
Furthermore, the plugin demonstrates no nonce checks or capability checks. While the attack surface appears to be zero based on the provided entry points, this lack of authorization and validation mechanisms is a risky practice. If any new entry points were introduced in future versions or if the analysis is incomplete, these omissions could be easily exploited. The vulnerability history is currently clean, which is good, but the lack of basic security checks like output escaping and authorization means that even a single development oversight could lead to a critical vulnerability. The plugin's strengths lie in its avoidance of common vulnerabilities like SQL injection and external request risks, but its weakness in output sanitization and authorization represents a substantial risk that should be addressed.
Key Concerns
- All outputs unescaped
- No nonce checks
- No capability checks
Kalendarium CZ Security Vulnerabilities
Kalendarium CZ Code Analysis
Output Escaping
Kalendarium CZ Attack Surface
WordPress Hooks 1
Maintenance & Trust
Kalendarium CZ Maintenance & Trust
Maintenance Signals
Community Trust
Kalendarium CZ Alternatives
Kalendář / Calendar
kalendar-cz
CZ
CPT Calender Widget for WordPress
cpt-calender-widget
Create Custom Post and and select CPT from dropdown.
ARCW Popover Addon
arcw-popover-addon
Popover Addon for Archives Calendar Widget
LCS Fast Calendar Widget for Events Manager
lcs-em-widget-calendar
This plugin adds a fast sidebar calendar widget to replace the one that comes with Events Manager.
Custom Sidebars – Dynamic Sidebar Classic Widget Area Manager
custom-sidebars
Flexible sidebars for custom classic widget configurations on any page or post. Create custom sidebars with ease!
Kalendarium CZ Developer Profile
1 plugin · 100 total installs
How We Detect Kalendarium CZ
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
today<div id="today">
<h6></h6></div>