notikumiWP Security & Risk Analysis

wordpress.org/plugins/notikumi

notikumi.com es una agenda cultural. Llévate su contenido a tu blog. Exposiciones, conciertos, obras de teatro, cine, deportes, infantil, festivales..

10 active installs v1.0.5 PHP + WP 3+ Updated May 20, 2012
culturacultureeventoseventsnotikumi
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is notikumiWP Safe to Use in 2026?

Generally Safe

Score 85/100

notikumiWP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The plugin 'notikumi' v1.0.5 exhibits a generally good security posture with a very small attack surface and no registered CVEs. The lack of dangerous functions, file operations, and external HTTP requests is a positive indicator. Crucially, all SQL queries are properly prepared, and there are no known unpatched vulnerabilities. However, a significant concern arises from the static analysis regarding output escaping, where 0% of the 15 identified outputs are properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be rendered directly into the HTML without sanitization.

The taint analysis reveals one flow with an unsanitized path, although it is not classified as critical or high severity. This suggests a potential, albeit likely minor, information disclosure or path traversal risk. The absence of nonce and capability checks on the single shortcode is also a point of concern, as it means the shortcode's functionality could be triggered by any user, regardless of their permissions or intent, potentially leading to unintended actions or information leakage if the shortcode's logic is not inherently secure.

Overall, while the plugin avoids common pitfalls like unpatched vulnerabilities and raw SQL queries, the lack of output escaping and the absence of authentication/authorization checks on its single entry point are critical weaknesses that significantly increase the risk profile. The plugin's history of zero vulnerabilities might suggest a lack of rigorous testing or that past issues were minor and unreported. The primary focus for improvement should be implementing robust output sanitization and securing the shortcode's execution context.

Key Concerns

  • Unescaped output
  • No capability checks on shortcode
  • Flow with unsanitized path
Vulnerabilities
None known

notikumiWP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

notikumiWP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

0% escaped15 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<admin.html> (html\admin.html.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

notikumiWP Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[NTK] notikumiWP.php:103
WordPress Hooks 3
actionnotikumiWP/notikumiWP.phpnotikumiWP.php:98
actionadmin_menunotikumiWP.php:99
actionadmin_initnotikumiWP.php:100
Maintenance & Trust

notikumiWP Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedMay 20, 2012
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

notikumiWP Developer Profile

Luke Stevenson

3 plugins · 20 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect notikumiWP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/notikumi/css/styles.css/wp-content/plugins/notikumi/css/colorpicker/css/colorpicker.css/wp-content/plugins/notikumi/js/notikumi_fn_widget.js/wp-content/plugins/notikumi/js/notikumi_init_widget.js
Script Paths
/wp-content/plugins/notikumi/js/notikumi_fn_widget.js/wp-content/plugins/notikumi/js/notikumi_init_widget.js/wp-content/plugins/notikumi/js/colorpicker/colorpicker.js/wp-content/plugins/notikumi/js/jquery/jquery.ui.autocomplete.min.js
Version Parameters
notikumi/styles.css?ver=notikumi/css/colorpicker/css/colorpicker.css?ver=notikumi/js/notikumi_fn_widget.js?ver=notikumi/js/notikumi_init_widget.js?ver=notikumi/js/colorpicker/colorpicker.js?ver=notikumi/js/jquery/jquery.ui.autocomplete.min.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- save to options when the form is sent --><!-- si envían formulario --><!-- Tratamiento del formulario enviado --><!-- Calculo de la firma -->+8 more
JS Globals
var NotikumiWPimpl
Shortcode Output
[NTK]
FAQ

Frequently Asked Questions about notikumiWP