
Link Google Calendar Security & Risk Analysis
wordpress.org/plugins/link-google-calendarA plugin that allows administrator to set Google Calendar embedded link in admin back-end and use shortcode to place on a page, post or sidebar.
Is Link Google Calendar Safe to Use in 2026?
Generally Safe
Score 85/100Link Google Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "link-google-calendar" plugin v2.0.0 presents a mixed security posture. On the positive side, it has a small attack surface with no unprotected entry points, no dangerous functions, no file operations, no external HTTP requests, and a complete lack of known vulnerabilities (CVEs). This suggests a generally well-maintained and less exposed plugin. However, significant concerns arise from the static analysis. All SQL queries are executed without prepared statements, which is a major risk for SQL injection vulnerabilities. Furthermore, a significant portion of output escaping is missing, creating potential for cross-site scripting (XSS) attacks. The taint analysis reveals flows with unsanitized paths, though thankfully, no critical or high severity issues were identified in this area, indicating that while data handling might be loose, it has not yet led to severe exploitable paths.
The absence of known vulnerabilities is a strong positive, implying either diligent security practices or a lack of targeted attacks. However, the identified code quality issues, particularly the lack of prepared statements for SQL and insufficient output escaping, are fundamental security weaknesses that could be easily exploited if an attacker were to find a suitable entry point. While the plugin is not currently flagged with known issues, these inherent code weaknesses represent a substantial underlying risk that should be addressed to improve its overall security robustness.
Key Concerns
- SQL queries without prepared statements
- Low percentage of properly escaped output
- Taint flows with unsanitized paths
- No nonce checks
- No capability checks
Link Google Calendar Security Vulnerabilities
Link Google Calendar Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Link Google Calendar Attack Surface
Shortcodes 6
WordPress Hooks 4
Maintenance & Trust
Link Google Calendar Maintenance & Trust
Maintenance Signals
Community Trust
Link Google Calendar Alternatives
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
ICS Calendar
ics-calendar
Add the calendar you already use to Any WordPress site! Google Calendar, Microsoft 365, iCloud and more… no API keys or complicated setup required.
Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar
booking-manager
Showing events listing from .ics feeds or sync bookings from different sources to your website
Pretty Google Calendar
pretty-google-calendar
Embedded Google Calendars that don't suck.
Events Calendar for Google
events-calendar-for-google
Events Calendar for Google implements google calender to your wordpress website using different style and layouts. Get connected to your audience usin …
Link Google Calendar Developer Profile
3 plugins · 360 total installs
How We Detect Link Google Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/link-google-calendar/css/lgc-admin-styles.csslink-google-calendar/css/lgc-admin-styles.css?ver=HTML / DOM Fingerprints
gcl-admin-sectiongcl-logo-sectiongcl-admin-body-section<div align="center">[lgc][lgc_1][lgc_2]