
Localist Calendar for WordPress Security & Risk Analysis
wordpress.org/plugins/localist-calendarThe most powerful way to highlight events on your WordPress website.
Is Localist Calendar for WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Localist Calendar for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'localist-calendar' v1.0 plugin presents a mixed security posture. On the positive side, it exhibits strong adherence to secure coding practices with a high percentage of SQL queries using prepared statements and output escaping. The absence of known CVEs and a clean vulnerability history, coupled with no recorded critical or high severity taint flows, suggests a generally well-developed and tested plugin.
However, there are notable areas of concern that warrant attention. The presence of the 'unserialize' function is a significant risk, as it can lead to Remote Code Execution (RCE) if not handled with extreme care and validated input. Furthermore, the complete lack of nonce checks on its (currently zero) entry points, and only one capability check overall, indicates a potential weakness in authorization and protection against Cross-Site Request Forgery (CSRF) attacks, should new entry points be introduced or existing ones become exploitable.
Overall, while the plugin appears to have a clean track record and good internal coding standards for SQL and output handling, the potential for 'unserialize' vulnerabilities and the lack of robust authorization checks on its entry points present tangible risks. The current low attack surface mitigates immediate critical threats, but any future expansion or unforeseen exploit path could leverage these weaknesses.
Key Concerns
- Unserialize function used
- No nonce checks on entry points
- Limited capability checks
Localist Calendar for WordPress Security Vulnerabilities
Localist Calendar for WordPress Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Localist Calendar for WordPress Attack Surface
WordPress Hooks 2
Maintenance & Trust
Localist Calendar for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Localist Calendar for WordPress Alternatives
The Events Calendar
the-events-calendar
The Events Calendar: #1 calendar plugin for WordPress. Create/manage events (virtual too!) on your site with the free plugin.
LatePoint – Calendar Booking Plugin for Appointments and Events
latepoint
Optimize your appointment scheduling with our plugin. Sync calendars, automate reminders, and keep your bookings organized.
Events Manager – Calendar, Bookings, Tickets, and more!
events-manager
Events calendar with bookings, scheduling, appointments, event registration, tickets, recurring events, and venue management.
Booking Calendar
booking
Original "Booking Calendar" plugin. Easily manage full-day bookings, time-slot appointments, or events in our all-in-one, outstanding booking system.
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
Localist Calendar for WordPress Developer Profile
1 plugin · 20 total installs
How We Detect Localist Calendar for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/localist-calendar/js/localist-script.js/wp-content/plugins/localist-calendar/css/localist-style.css/wp-content/plugins/localist-calendar/js/localist-script.jsHTML / DOM Fingerprints
localist-calendar-widgetlocalist-widget-titlelocalist-widget-event-datelocalist-widget-event-titlelocalist-widget-event-locationlocalist-widget-event-descriptiondata-localist-widget-iddata-localist-widget-urldata-localist-widget-templatedata-localist-widget-communitydata-localist-widget-resultsdata-localist-widget-day+15 morelocalistCalendar[localist_calendar]