MusicIDB Events Calendar Security & Risk Analysis

wordpress.org/plugins/musicidb-calendar

An interactive website calendar for live music and event listings.

90 active installs v2.5.14 PHP 7.3+ WP 4.0+ Updated Dec 19, 2025
calendardatabaseindustrymusicmusicidb
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is MusicIDB Events Calendar Safe to Use in 2026?

Generally Safe

Score 100/100

MusicIDB Events Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The musicidb-calendar plugin, version 2.5.14, exhibits a generally good security posture based on the provided static analysis. All identified entry points, including AJAX handlers and shortcodes, appear to have proper authentication and permission checks, which is a significant strength. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests further contributes to its secure design. Taint analysis and vulnerability history show no reported issues, indicating a lack of known vulnerabilities and a seemingly robust development process concerning data sanitization and security practices.

However, there is a moderate concern regarding output escaping, where 76% of outputs are properly escaped, leaving 24% potentially unescaped. While the taint analysis did not reveal any critical or high severity unsanitized flows, a significant portion of unescaped output presents a potential risk of cross-site scripting (XSS) vulnerabilities if sensitive data is rendered without proper sanitization, especially in contexts where user-provided input might influence the output. The presence of one external HTTP request, although not explicitly detailed as a risk in this analysis, could also be a vector for certain types of attacks if not handled securely. Overall, the plugin is well-defended against common attack vectors but requires attention to the unescaped output areas to achieve a higher level of security.

Key Concerns

  • Unescaped output detected (24%)
  • One external HTTP request found
Vulnerabilities
None known

MusicIDB Events Calendar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

MusicIDB Events Calendar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
54
172 escaped
Nonce Checks
7
Capability Checks
2
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

76% escaped226 total outputs
Attack Surface

MusicIDB Events Calendar Attack Surface

Entry Points7
Unprotected0

AJAX Handlers 5

authwp_ajax_load_events_listclass-musicidb-integration.php:86
noprivwp_ajax_load_events_listclass-musicidb-integration.php:87
authwp_ajax_load_event_detailsclass-musicidb-integration.php:89
noprivwp_ajax_load_event_detailsclass-musicidb-integration.php:90
authwp_ajax_load_shortcode_optionsclass-musicidb-integration.php:92

Shortcodes 2

[musicidb] class-musicidb-integration.php:1064
[musicidb-featured-slider] class-musicidb-integration.php:1065
WordPress Hooks 10
actionadmin_menuclass-musicidb-integration.php:70
actioninitclass-musicidb-integration.php:73
actionadmin_initclass-musicidb-integration.php:76
actionupdate_option_musicidb_optionsclass-musicidb-integration.php:79
actionadmin_enqueue_scriptsclass-musicidb-integration.php:82
actionwp_enqueue_scriptsclass-musicidb-integration.php:83
actionmedia_buttonsclass-musicidb-integration.php:262
filtermusicidb_hover_cards_setsmusicidb-view-compact.php:126
filtermusicidb_hover_cards_setsmusicidb-view-full.php:148
filtermusicidb_hover_cards_setsmusicidb-view-posterboard.php:147
Maintenance & Trust

MusicIDB Events Calendar Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 19, 2025
PHP min version7.3
Downloads7K

Community Trust

Rating100/100
Number of ratings28
Active installs90
Developer Profile

MusicIDB Events Calendar Developer Profile

megabase

2 plugins · 130 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MusicIDB Events Calendar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/musicidb-calendar/css/events-list.css/wp-content/plugins/musicidb-calendar/css/musicidb.css/wp-content/plugins/musicidb-calendar/js/musicidb-calendar.js/wp-content/plugins/musicidb-calendar/js/musicidb-calendar.min.js
Script Paths
/wp-content/plugins/musicidb-calendar/js/musicidb-calendar.min.js/wp-content/plugins/musicidb-calendar/js/musicidb-calendar.js
Version Parameters
musicidb-calendar/css/events-list.css?ver=musicidb-calendar/css/musicidb.css?ver=musicidb-calendar/js/musicidb-calendar.min.js?ver=musicidb-calendar/js/musicidb-calendar.js?ver=

HTML / DOM Fingerprints

CSS Classes
musicidb-calendar-wrapmusicidb-event-listmusicidb-event-itemmusicidb-event-titlemusicidb-event-datemusicidb-event-timemusicidb-event-locationmusicidb-event-details
HTML Comments
<!-- MusicIDB Events Calendar --><!-- MusicIDB API Key Input --><!-- Default Entity Input --><!-- Additional Venues Input -->+3 more
Data Attributes
data-musicidb-api-keydata-musicidb-entity-iddata-musicidb-entity-type
JS Globals
musicidbCalendar
REST Endpoints
/wp-json/musicidb/v1/events/wp-json/musicidb/v1/event/
Shortcode Output
[musicidb_calendar][musicidb_events_list]
FAQ

Frequently Asked Questions about MusicIDB Events Calendar