
NeonCRM Events Widget Security & Risk Analysis
wordpress.org/plugins/neoncrm-events-widgetDisplays a feed of upcoming events retrieved from NeonCRM.
Is NeonCRM Events Widget Safe to Use in 2026?
Generally Safe
Score 85/100NeonCRM Events Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The NeonCRM Events Widget plugin v0.20 exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding SQL query handling, utilizing prepared statements exclusively, and has no recorded vulnerabilities (CVEs). The absence of file operations and external HTTP requests also reduces the attack surface. However, significant concerns arise from the static analysis. The presence of the `create_function` dangerous function is a notable risk, as it can lead to code injection vulnerabilities if user-supplied data is used within it without proper sanitization. Furthermore, a low rate of output escaping (only 25%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into web pages rendered by the plugin.
The plugin's attack surface is reported as zero for entry points, which is excellent, but this is contradicted by the lack of capability checks and nonce checks. This suggests that any potential entry points, even if not immediately obvious from the static analysis, might be unprotected. The vulnerability history being clean is a strong positive signal, but it doesn't negate the risks identified in the code analysis. The combination of a dangerous function and poor output escaping, alongside a lack of essential security checks, presents a significant risk despite the absence of known CVEs.
Key Concerns
- Dangerous function create_function used
- Low output escaping percentage
- Missing nonce checks
- Missing capability checks
NeonCRM Events Widget Security Vulnerabilities
NeonCRM Events Widget Code Analysis
Dangerous Functions Found
Output Escaping
NeonCRM Events Widget Attack Surface
WordPress Hooks 1
Maintenance & Trust
NeonCRM Events Widget Maintenance & Trust
Maintenance Signals
Community Trust
NeonCRM Events Widget Alternatives
NeonCRM Sign-In
neoncrm-sign-in
Sign in to WordPress using a NeonCRM constituent account.
CiviEvent Widget
civievent-widget
Display widgets for CiviCRM events: the next public event or a whole list. Embed widgets as shortcodes, too!
Nonprofit Manager
nonprofit-manager
Comprehensive nonprofit management solution for memberships, donations, newsletters, and events.
Flamingo
flamingo
A trustworthy message storage plugin for Contact Form 7.
The Events Calendar
the-events-calendar
The Events Calendar: #1 calendar plugin for WordPress. Create/manage events (virtual too!) on your site with the free plugin.
NeonCRM Events Widget Developer Profile
2 plugins · 70 total installs
How We Detect NeonCRM Events Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/neoncrm-events-widget/neon-events.css/wp-content/plugins/neoncrm-events-widget/neon-events.jsneoncrm-events-widget/neon-events.css?ver=neoncrm-events-widget/neon-events.js?ver=HTML / DOM Fingerprints
neoncrm-events-widget-containerdata-org-iddata-api-keydata-per-pagedata-cache-timedata-event-namedata-event-start+10 moreneonEventsWidget[neoncrm_events_widget]