
LCS Fast Calendar Widget for Events Manager Security & Risk Analysis
wordpress.org/plugins/lcs-em-widget-calendarThis plugin adds a fast sidebar calendar widget to replace the one that comes with Events Manager.
Is LCS Fast Calendar Widget for Events Manager Safe to Use in 2026?
Generally Safe
Score 100/100LCS Fast Calendar Widget for Events Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lcs-em-widget-calendar" plugin v1.0 demonstrates several positive security practices, including a complete lack of detected CVEs and no evidence of bundled libraries. The static analysis also shows a very small attack surface with zero entry points detected. Importantly, all SQL queries are reported to use prepared statements, which is a strong defense against SQL injection vulnerabilities.
However, the analysis also reveals significant concerns. The most pressing issue is the low percentage of properly escaped output (19%), indicating a high risk of cross-site scripting (XSS) vulnerabilities. The taint analysis, despite a small number of flows analyzed, flagged two flows with unsanitized paths, which could potentially lead to other injection vulnerabilities or information disclosure. Furthermore, the complete absence of nonce checks and capability checks on all entry points is a critical oversight, leaving the plugin exposed to CSRF attacks and unauthorized privilege escalation if any entry points were to be discovered or added in future versions.
Overall, while the plugin has a clean vulnerability history and good practices in SQL handling, the high rate of unescaped output and the lack of fundamental security checks like nonces and capability checks present a substantial security risk. The minimal attack surface and lack of CVEs are strengths, but the identified code-level weaknesses require immediate attention to improve its security posture.
Key Concerns
- Low output escaping (19%)
- Unsanitized paths in taint analysis
- No nonce checks
- No capability checks
LCS Fast Calendar Widget for Events Manager Security Vulnerabilities
LCS Fast Calendar Widget for Events Manager Code Analysis
Output Escaping
Data Flow Analysis
LCS Fast Calendar Widget for Events Manager Attack Surface
WordPress Hooks 4
Maintenance & Trust
LCS Fast Calendar Widget for Events Manager Maintenance & Trust
Maintenance Signals
Community Trust
LCS Fast Calendar Widget for Events Manager Alternatives
Lightweight Sidebar Manager
sidebar-manager
Create new sidebar areas and display them conditionally on certain pages. Works with all themes.
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
Events Widgets For Elementor And The Events Calendar
events-widgets-for-elementor-and-the-events-calendar
The Events Calendar Elementor widgets help you manage and display an upcoming events list with date, time, venue and event ticket booking details.
Simple Image Widget
simple-image-widget
A simple widget that makes it a breeze to add images to your sidebars.
Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered)
wp-event-solution
Create and manage events with a flexible WordPress events calendar plugin. Add recurring events, RSVP, ticket booking, and WooCommerce ticket selling …
LCS Fast Calendar Widget for Events Manager Developer Profile
3 plugins · 20 total installs
How We Detect LCS Fast Calendar Widget for Events Manager
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.