Nic-app Crono Security & Risk Analysis

wordpress.org/plugins/nic-app-crono

Nic-app Crono is a plugin that allows you to unify different calendars (Google Calendar, Apple iCloud, Exchange, Office 365 / Outlook) into a single c …

0 active installs v1.0.2 PHP + WP 5.0+ Updated Sep 28, 2020
calendarscronofymultiple-calendarssynchronizationwoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Nic-app Crono Safe to Use in 2026?

Generally Safe

Score 85/100

Nic-app Crono has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "nic-app-crono" plugin version 1.0.2 exhibits a generally strong security posture based on the provided static analysis. The plugin demonstrates good practices by employing prepared statements for all SQL queries and properly escaping the vast majority of its output. Furthermore, it correctly implements nonce and capability checks, and it has no known vulnerabilities recorded, indicating a history of secure development or effective patching.

However, a notable concern arises from the taint analysis, which identified one flow with unsanitized paths. While not classified as critical or high severity, an unsanitized path could potentially lead to unintended file access or manipulation if an attacker can influence the path. The presence of file operations, even if not directly linked to the unsanitized path in the analysis, warrants careful consideration. The limited attack surface and absence of other critical code signals are positive indicators, but the single taint flow represents a potential weakness that should be addressed.

In conclusion, "nic-app-crono" v1.0.2 is a relatively secure plugin with a clean vulnerability history and strong adherence to many security best practices. The primary area for improvement lies in thoroughly sanitizing all user-influenced paths to eliminate any risk associated with file operations or other sensitive actions. Addressing this single taint flow will further solidify its security.

Key Concerns

  • Flow with unsanitized path detected
Vulnerabilities
None known

Nic-app Crono Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Nic-app Crono Release Timeline

v1.0.2Current
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Nic-app Crono Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
63 escaped
Nonce Checks
1
Capability Checks
1
File Operations
4
External Requests
3
Bundled Libraries
0

Output Escaping

97% escaped65 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
ShowLogFile (admin/class-nicappcrono-admin.php:1312)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Nic-app Crono Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[NicappAuth] public/class-nicappcrono-public.php:57
WordPress Hooks 17
actioninitadmin/class-nicappcrono-admin.php:58
actionadmin_menuadmin/class-nicappcrono-admin.php:62
actionadmin_initadmin/class-nicappcrono-admin.php:66
actionadd_meta_boxes_nicappcronocalendarsadmin/class-nicappcrono-admin.php:70
actionsave_post_nicappcronocalendarsadmin/class-nicappcrono-admin.php:74
filtermanage_nicappcronocalendars_posts_columnsadmin/class-nicappcrono-admin.php:78
actionmanage_nicappcronocalendars_posts_custom_columnadmin/class-nicappcrono-admin.php:82
actionadmin_initadmin/class-nicappcrono-admin.php:86
actionadmin_noticesadmin/class-nicappcrono-admin.php:586
actionadmin_noticesadmin/class-nicappcrono-admin.php:607
actionadmin_noticesadmin/class-nicappcrono-admin.php:628
actionplugins_loadedincludes/class-nicappcrono.php:152
actionadmin_enqueue_scriptsincludes/class-nicappcrono.php:166
actionadmin_enqueue_scriptsincludes/class-nicappcrono.php:167
actionnicappcronoCronJobincludes/class-nicappcrono.php:168
actionwp_enqueue_scriptsincludes/class-nicappcrono.php:182
actionwp_enqueue_scriptsincludes/class-nicappcrono.php:183

Scheduled Events 1

nicappcronoCronJob
Maintenance & Trust

Nic-app Crono Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedSep 28, 2020
PHP min version
Downloads987

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Nic-app Crono Developer Profile

Efraim Bayarri

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Nic-app Crono

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nic-app-crono/admin/css/nicappcrono-admin.css/wp-content/plugins/nic-app-crono/admin/js/nicappcrono-admin.js
Script Paths
/wp-content/plugins/nic-app-crono/admin/js/nicappcrono-admin.js
Version Parameters
nicappcrono-admin.css?ver=nicappcrono-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
nicappcrono-admin-css
Data Attributes
data-plugin-name="Nicappcrono"data-plugin-version="1.0.2"
JS Globals
nicappcrono_admin_object
FAQ

Frequently Asked Questions about Nic-app Crono