
Legacy Google Calendar Events 2.4 Security & Risk Analysis
wordpress.org/plugins/legacy-google-calendar-eventsFork of the Google Calendar Events 2.4 WordPress plugin. Intended for backwards compatibility only.
Is Legacy Google Calendar Events 2.4 Safe to Use in 2026?
Generally Safe
Score 85/100Legacy Google Calendar Events 2.4 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The legacy-google-calendar-events plugin version 2.4.1 presents a mixed security posture. On the positive side, it demonstrates good practices with 100% of its SQL queries using prepared statements and a significant majority of its output being properly escaped. The absence of known CVEs and any recorded vulnerabilities in its history is also a strong indicator of a historically secure plugin.
However, there are significant areas of concern, primarily revolving around its attack surface. With 4 out of 6 total entry points lacking authentication checks, the plugin is susceptible to unauthorized access and potential exploitation. The presence of dangerous functions like `unserialize` and `create_function` is a red flag, especially when coupled with unsanitized paths found in taint analysis. While no critical or high-severity taint flows were identified, the potential for these functions to be exploited if combined with unvalidated input cannot be ignored. The single nonce check on an AJAX handler is insufficient given the number of unprotected AJAX endpoints.
In conclusion, while the plugin has a clean vulnerability history and employs sound practices in areas like SQL handling and output escaping, the significant number of unprotected entry points and the presence of potentially dangerous functions introduce considerable risk. Addressing the authentication deficiencies on its AJAX handlers is paramount to improving its security.
Key Concerns
- 4 AJAX handlers without auth checks
- 2 Dangerous functions found
- 4 Flows with unsanitized paths
- 1 Nonce check for 4 unprotected AJAX handlers
- 74% output escaping is not 100%
Legacy Google Calendar Events 2.4 Security Vulnerabilities
Legacy Google Calendar Events 2.4 Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Legacy Google Calendar Events 2.4 Attack Surface
AJAX Handlers 4
Shortcodes 2
WordPress Hooks 34
Maintenance & Trust
Legacy Google Calendar Events 2.4 Maintenance & Trust
Maintenance Signals
Community Trust
Legacy Google Calendar Events 2.4 Alternatives
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
ICS Calendar
ics-calendar
Add the calendar you already use to Any WordPress site! Google Calendar, Microsoft 365, iCloud and more… no API keys or complicated setup required.
Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar
booking-manager
Showing events listing from .ics feeds or sync bookings from different sources to your website
Pretty Google Calendar
pretty-google-calendar
Embedded Google Calendars that don't suck.
Events Calendar for Google
events-calendar-for-google
Events Calendar for Google implements google calender to your wordpress website using different style and layouts. Get connected to your audience usin …
Legacy Google Calendar Events 2.4 Developer Profile
4 plugins · 51K total installs
How We Detect Legacy Google Calendar Events 2.4
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/legacy-google-calendar-events/css/gce-admin.css/wp-content/plugins/legacy-google-calendar-events/css/gce-admin-notices.css/wp-content/plugins/legacy-google-calendar-events/css/gce-frontend.css/wp-content/plugins/legacy-google-calendar-events/js/gce-admin.js/wp-content/plugins/legacy-google-calendar-events/js/gce-frontend.js/wp-content/plugins/legacy-google-calendar-events/js/gce-admin.js/wp-content/plugins/legacy-google-calendar-events/js/gce-frontend.jslegacy-google-calendar-events/css/gce-admin.css?ver=legacy-google-calendar-events/css/gce-admin-notices.css?ver=legacy-google-calendar-events/css/gce-frontend.css?ver=legacy-google-calendar-events/js/gce-admin.js?ver=legacy-google-calendar-events/js/gce-frontend.js?ver=HTML / DOM Fingerprints
gce-dismissible-noticegce-dismiss-noticegce_dismiss_admin_update_notices