LAUTI Calendar Security & Risk Analysis

wordpress.org/plugins/lauti-calendar

Display events from your LAUTI instance on your WordPress site as a list or timetable. Ships with simple, adjustable CSS.

0 active installs v1.0.0 PHP + WP 5.3+ Updated Nov 4, 2025
calendareventeventstimetable
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LAUTI Calendar Safe to Use in 2026?

Generally Safe

Score 100/100

LAUTI Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The "lauti-calendar" v1.0.0 plugin exhibits a strong adherence to several key WordPress security best practices based on the provided static analysis. The absence of any detected dangerous functions, the exclusive use of prepared statements for SQL queries, and the 100% proper output escaping of all identified outputs are highly positive indicators of secure coding. Furthermore, the lack of reported vulnerabilities in its history suggests a stable and well-maintained codebase to date. The limited attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events, further contributes to its current secure posture. However, a significant concern is the complete absence of nonce checks and capability checks. This, combined with the single external HTTP request which is also not explicitly secured by any form of authentication or authorization, represents a potential blind spot. While current analysis shows no exploitable flows, the lack of these fundamental security mechanisms leaves the plugin vulnerable to CSRF and unauthorized access if its functionality were to change or if new attack vectors were discovered that could leverage the external HTTP request.

In conclusion, the plugin's current implementation demonstrates good defensive coding in several areas, particularly in data handling and output. The negligible attack surface and clean vulnerability history are commendable. Nevertheless, the omission of nonce and capability checks, and the unprotected external HTTP request, are critical oversights that significantly undermine its overall security. These omissions represent a substantial risk, as they fail to implement basic safeguards against common web vulnerabilities that could be exploited by malicious actors. Addressing these specific weaknesses would drastically improve the plugin's security posture.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • External HTTP request without authentication
Vulnerabilities
None known

LAUTI Calendar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

LAUTI Calendar Release Timeline

v1.0.0Current
Code Analysis
Analyzed Mar 17, 2026

LAUTI Calendar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
146 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped146 total outputs
Attack Surface

LAUTI Calendar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionadmin_enqueue_scriptsincludes\class-lauti-calendar.php:131
actionadmin_enqueue_scriptsincludes\class-lauti-calendar.php:132
actionadmin_menuincludes\class-lauti-calendar.php:135
actionadmin_initincludes\class-lauti-calendar.php:138
actionwp_enqueue_scriptsincludes\class-lauti-calendar.php:152
actionwp_enqueue_scriptsincludes\class-lauti-calendar.php:153
Maintenance & Trust

LAUTI Calendar Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedNov 4, 2025
PHP min version
Downloads191

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

LAUTI Calendar Developer Profile

klasseundmethode

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LAUTI Calendar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lauti-calendar/css/lauti-calendar-admin.css/wp-content/plugins/lauti-calendar/js/lauti-calendar-admin.js
Script Paths
js/lauti-calendar-admin.js
Version Parameters
lauti-calendar/css/lauti-calendar-admin.css?ver=lauti-calendar/js/lauti-calendar-admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about LAUTI Calendar