LCS Fast Calendar Widget for Events Manager Security & Risk Analysis

wordpress.org/plugins/lcs-em-widget-calendar

This plugin adds a fast sidebar calendar widget to replace the one that comes with Events Manager.

0 active installs v1.0 PHP + WP 4.5+ Updated Unknown
calendareventsmanagersidebarwidget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is LCS Fast Calendar Widget for Events Manager Safe to Use in 2026?

Generally Safe

Score 100/100

LCS Fast Calendar Widget for Events Manager has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "lcs-em-widget-calendar" plugin v1.0 demonstrates several positive security practices, including a complete lack of detected CVEs and no evidence of bundled libraries. The static analysis also shows a very small attack surface with zero entry points detected. Importantly, all SQL queries are reported to use prepared statements, which is a strong defense against SQL injection vulnerabilities.

However, the analysis also reveals significant concerns. The most pressing issue is the low percentage of properly escaped output (19%), indicating a high risk of cross-site scripting (XSS) vulnerabilities. The taint analysis, despite a small number of flows analyzed, flagged two flows with unsanitized paths, which could potentially lead to other injection vulnerabilities or information disclosure. Furthermore, the complete absence of nonce checks and capability checks on all entry points is a critical oversight, leaving the plugin exposed to CSRF attacks and unauthorized privilege escalation if any entry points were to be discovered or added in future versions.

Overall, while the plugin has a clean vulnerability history and good practices in SQL handling, the high rate of unescaped output and the lack of fundamental security checks like nonces and capability checks present a substantial security risk. The minimal attack surface and lack of CVEs are strengths, but the identified code-level weaknesses require immediate attention to improve its security posture.

Key Concerns

  • Low output escaping (19%)
  • Unsanitized paths in taint analysis
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

LCS Fast Calendar Widget for Events Manager Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

LCS Fast Calendar Widget for Events Manager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

19% escaped21 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
calendar_init (lcs-em-widget-calendar.php:48)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

LCS Fast Calendar Widget for Events Manager Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterpre_option_dbem_categories_enabledlcs-em-widget-calendar.php:35
filterpre_option_dbem_tags_enabledlcs-em-widget-calendar.php:36
actioninitlcs-em-widget-calendar.php:137
actionwidgets_initlcs-em-widget-calendar.php:138
Maintenance & Trust

LCS Fast Calendar Widget for Events Manager Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

LCS Fast Calendar Widget for Events Manager Developer Profile

latcomsystems

3 plugins · 20 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect LCS Fast Calendar Widget for Events Manager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about LCS Fast Calendar Widget for Events Manager