
MDJM Extension – Google Calendar Sync Security & Risk Analysis
wordpress.org/plugins/mdjm-google-calendar-syncAutomatically adds your event bookings to your Google calendar and keeps them up to date.
Is MDJM Extension – Google Calendar Sync Safe to Use in 2026?
Generally Safe
Score 100/100MDJM Extension – Google Calendar Sync has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mdjm-google-calendar-sync plugin v2.3.8.1 exhibits a generally positive security posture with some notable areas of concern. The plugin demonstrates good practices by utilizing prepared statements for most SQL queries, ensuring a high percentage of properly escaped output, and including nonce checks. The absence of file operations and external HTTP requests further strengthens its security. However, the presence of one AJAX handler without authentication checks represents a significant potential entry point for attackers. While no critical or high severity taint flows were identified, the existence of a flow with an unsanitized path warrants attention, even if its severity is currently low.
The plugin benefits from a clean vulnerability history, with zero recorded CVEs. This suggests either a history of robust security development or a lack of targeted exploitation. However, relying solely on past history can be misleading, and the identified unprotected AJAX handler remains a tangible risk that could be exploited regardless of historical CVEs. Overall, the plugin has strengths in its data handling and output sanitization, but the unprotected AJAX endpoint is a critical weakness that needs to be addressed to improve its security.
Key Concerns
- Unprotected AJAX handler
- Flow with unsanitized path
MDJM Extension – Google Calendar Sync Security Vulnerabilities
MDJM Extension – Google Calendar Sync Release Timeline
MDJM Extension – Google Calendar Sync Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
MDJM Extension – Google Calendar Sync Attack Surface
AJAX Handlers 1
REST API Routes 1
WordPress Hooks 16
Scheduled Events 2
Maintenance & Trust
MDJM Extension – Google Calendar Sync Maintenance & Trust
Maintenance Signals
Community Trust
MDJM Extension – Google Calendar Sync Alternatives
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
ICS Calendar
ics-calendar
Add the calendar you already use to Any WordPress site! Google Calendar, Microsoft 365, iCloud and more… no API keys or complicated setup required.
Sugar Calendar – Events Calendar, Event Tickets, and Events Management Platform
sugar-calendar-lite
Easily manage events and sell tickets on your WordPress site. Sugar Calendar is easy-to-use, reliable, and exceptionally powerful. See for yourself.
Eventin – Event Calendar, Event Registration, Tickets & Booking (AI Powered)
wp-event-solution
Events calendar plugin for WordPress to manage events, bookings, registrations, scheduling, virtual events, and tickets sales.
EventON – Events Calendar
eventon-lite
Create beautiful, responsive event calendars with unlimited events, repeating schedules, virtual support, and a sleek minimal design!
MDJM Extension – Google Calendar Sync Developer Profile
2 plugins · 50 total installs
How We Detect MDJM Extension – Google Calendar Sync
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mdjm-google-calendar-sync/libs/Google/vendor/autoload.phpHTML / DOM Fingerprints
<!-- Admin notices --><!-- Load stored tokens into class properties (for UI / notices). --><!-- Handle auth callback OR refresh token if needed. --><!-- Initialise Google Calendar service and settings. -->+6 moredata-gcal-optionsmdjm_gcal_options/wp-json/mdjm-gcal-integration/v1/calendar-feed