Miramedia Event Manager for TEDx Security & Risk Analysis

wordpress.org/plugins/miramedia-event-manager-for-tedx

Event management for TEDx organizers. Manage talks, speakers, and sponsors with custom Gutenberg blocks and advanced filtering.

0 active installs v1.5 PHP 7.4+ WP 5.9+ Updated Unknown
custom-post-typesevent-managementgutenberg-blocksspeakerstedx
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Miramedia Event Manager for TEDx Safe to Use in 2026?

Generally Safe

Score 100/100

Miramedia Event Manager for TEDx has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "miramedia-event-manager-for-tedx" plugin v1.5 exhibits a generally strong security posture in several key areas. The absence of dangerous functions, file operations, and external HTTP requests is commendable. Furthermore, the plugin demonstrates excellent practices regarding SQL queries, with 100% of them using prepared statements, and 100% of output is properly escaped, which significantly mitigates risks of SQL injection and cross-site scripting (XSS). The presence of nonce and capability checks on some entry points also indicates an awareness of security best practices.

However, a significant concern arises from the substantial attack surface exposed by the REST API routes. All 6 REST API routes lack permission callbacks, meaning they are accessible without any authentication or authorization checks. This creates a high risk of unauthorized access and manipulation of event data. The static analysis also reveals 6 unprotected entry points, contributing to this elevated risk. The lack of recorded vulnerability history is positive, but it does not negate the immediate risks identified in the current code analysis.

In conclusion, while the plugin has strengths in data handling and output sanitization, the unprotected REST API routes represent a critical security weakness. This lack of authentication on a significant portion of the attack surface is the primary driver of risk for this version. Addressing these unprotected entry points should be the highest priority to improve the plugin's overall security.

Key Concerns

  • REST API routes without permission callbacks
  • Unprotected entry points (total)
Vulnerabilities
None known

Miramedia Event Manager for TEDx Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Miramedia Event Manager for TEDx Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
82 escaped
Nonce Checks
3
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped82 total outputs
Attack Surface
6 unprotected

Miramedia Event Manager for TEDx Attack Surface

Entry Points8
Unprotected6

REST API Routes 6

GET/wp-json/wp/v2/mmevmt_talk_yearapi.php:21
GET/wp-json/wp/v2/mmevmt_person_typeapi.php:77
GET/wp-json/wp/v2/mmevmt_company_typeapi.php:132
GET/wp-json/wp/v2/mmevmt-companies-filteredapi.php:175
GET/wp-json/wp/v2/mmevmt-people-filteredapi.php:192
GET/wp-json/wp/v2/mmevmt-talks-filteredapi.php:209

Shortcodes 2

[mmevmt_youtube] shortcodes.php:30
[mmevmt_speaker] shortcodes.php:85
WordPress Hooks 27
actioninitapi.php:8
actionrest_api_initapi.php:20
actioninitapi.php:64
actionrest_api_initapi.php:76
actioninitapi.php:119
actionrest_api_initapi.php:131
actionrest_api_initapi.php:173
filterblock_categories_allblocks.php:19
actioninitblocks.php:86
actioninitcpt.php:93
filterrest_mmevmt_company_querycpt.php:98
filterrest_mmevmt_person_querycpt.php:113
filterrest_mmevmt_talk_querycpt.php:128
actionrest_api_initcpt.php:142
actioninitcpt.php:149
actionsave_post_mmevmt_personcpt.php:228
actionsave_post_mmevmt_companycpt.php:317
actionsave_post_mmevmt_talkcpt.php:413
actionwp_enqueue_scriptsmiramedia-event-manager-for-tedx.php:46
filtercomments_openmiramedia-event-manager-for-tedx.php:60
filterpings_openmiramedia-event-manager-for-tedx.php:61
filtercomments_arraymiramedia-event-manager-for-tedx.php:64
actionadmin_menumiramedia-event-manager-for-tedx.php:67
actionadmin_initmiramedia-event-manager-for-tedx.php:72
actionwidgets_initmiramedia-event-manager-for-tedx.php:85
actioninitmiramedia-event-manager-for-tedx.php:91
filteruse_block_editor_for_post_typemiramedia-event-manager-for-tedx.php:100
Maintenance & Trust

Miramedia Event Manager for TEDx Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads101

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Miramedia Event Manager for TEDx Developer Profile

Dominic Johnson

2 plugins · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Miramedia Event Manager for TEDx

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/miramedia-event-manager-for-tedx/assets/style.css
Version Parameters
miramedia-event-manager-for-tedx/assets/style.css?ver=

HTML / DOM Fingerprints

REST Endpoints
/wp-json/wp/v2/mmevmt_talk_year/wp-json/wp/v2/mmevmt_person_type/wp-json/wp/v2/mmevmt_company_type
FAQ

Frequently Asked Questions about Miramedia Event Manager for TEDx