
Localendar Calendar for WordPress Security & Risk Analysis
wordpress.org/plugins/localendar-for-wordpressThanks for checking out the localendar calendar plugin for WordPress. We have been powering web calendars for thousands of sites for over 16 years, an …
Is Localendar Calendar for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Localendar Calendar for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "localendar-for-wordpress" plugin v1.4 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, SQL injection vulnerabilities, file operations, and external HTTP requests are positive indicators. The plugin also correctly utilizes prepared statements for its SQL queries. However, the static analysis reveals a significant concern regarding output escaping, with only 66% of outputs being properly escaped. This suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is involved in the unescaped outputs. The lack of nonce checks and capability checks, while not directly flagged as issues in the current analysis (likely due to no AJAX or REST API endpoints being identified as unprotected), represents a potential weakness that could be exploited if new entry points are introduced or if the existing shortcode interacts with sensitive data or actions without proper authorization.
The vulnerability history is completely clean, indicating no known past exploits or issues with this plugin. This, combined with the apparent adherence to secure coding practices in many areas, suggests a development team that is either diligent or fortunate. However, the unescaped output remains a significant concern that cannot be overlooked. The absence of any taint analysis results is noteworthy, but this may simply mean the analysis tool did not identify any flows, not that they don't exist within the unescaped output.
In conclusion, while the plugin demonstrates strengths in many core security areas like SQL and avoiding dangerous functions, the considerable percentage of unescaped output poses a real risk of XSS vulnerabilities. The lack of explicit nonce and capability checks on the identified shortcode, though not directly exploitable without further context, is a potential area for future security hardening. The clean vulnerability history is a positive, but should not overshadow the identified risks within the current code.
Key Concerns
- Significant unescaped output detected
- Missing nonce checks on shortcode
- Missing capability checks on shortcode
Localendar Calendar for WordPress Security Vulnerabilities
Localendar Calendar for WordPress Code Analysis
Output Escaping
Localendar Calendar for WordPress Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Localendar Calendar for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Localendar Calendar for WordPress Alternatives
Tockify Events Calendar
tockify-events-calendar
Tockify Calendar is a modern attractive website calendar. Beautiful. Intuitive. Super-Customizable. Lightning Fast.
iCal for Events Calendar
ical-for-events-calendar
Add an iCal feed to your site for the Events Calendar plugin
Timetable and Event Schedule by MotoPress
mp-timetable
Smart event organizer and time-management tool with a clean minimalist design for featuring your timetables and upcoming events.
Event Organiser
event-organiser
Create and maintain events, including complex reoccurring patterns, venue management (with Google Maps or OpenStreetMap), calendars and customisable e …
The Events Calendar Shortcode & Block
the-events-calendar-shortcode
Add shortcode, block, Elementor and Bricks functionality to The Events Calendar Plugin, so you can easily list and promote your events anywhere.
Localendar Calendar for WordPress Developer Profile
5 plugins · 610 total installs
How We Detect Localendar Calendar for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/localendar-for-wordpress/lib/images/icon.png/wp-content/plugins/localendar-for-wordpress/lib/js/admin.js/wp-content/plugins/localendar-for-wordpress/lib/js/iColorPicker.js/wp-content/plugins/localendar-for-wordpress/lib/js/admin.js/wp-content/plugins/localendar-for-wordpress/lib/js/iColorPicker.jsHTML / DOM Fingerprints
localendar-typeslocalendar-styleslocalendar-eventslocalendar-link-textlocalendar-iframe-widthlocalendar-iframe-heightlocalendar-querylocalendar-bgm-events+1 morelocalendar-userlocalendar-styleslocalendar-eventslocalendar-link-textlocalendar-iframe-widthlocalendar-iframe-height+3 moreinsertCalendar[localendarusername=type=style=