
notikumiWP Security & Risk Analysis
wordpress.org/plugins/notikuminotikumi.com es una agenda cultural. Llévate su contenido a tu blog. Exposiciones, conciertos, obras de teatro, cine, deportes, infantil, festivales..
Is notikumiWP Safe to Use in 2026?
Generally Safe
Score 85/100notikumiWP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'notikumi' v1.0.5 exhibits a generally good security posture with a very small attack surface and no registered CVEs. The lack of dangerous functions, file operations, and external HTTP requests is a positive indicator. Crucially, all SQL queries are properly prepared, and there are no known unpatched vulnerabilities. However, a significant concern arises from the static analysis regarding output escaping, where 0% of the 15 identified outputs are properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data could be rendered directly into the HTML without sanitization.
The taint analysis reveals one flow with an unsanitized path, although it is not classified as critical or high severity. This suggests a potential, albeit likely minor, information disclosure or path traversal risk. The absence of nonce and capability checks on the single shortcode is also a point of concern, as it means the shortcode's functionality could be triggered by any user, regardless of their permissions or intent, potentially leading to unintended actions or information leakage if the shortcode's logic is not inherently secure.
Overall, while the plugin avoids common pitfalls like unpatched vulnerabilities and raw SQL queries, the lack of output escaping and the absence of authentication/authorization checks on its single entry point are critical weaknesses that significantly increase the risk profile. The plugin's history of zero vulnerabilities might suggest a lack of rigorous testing or that past issues were minor and unreported. The primary focus for improvement should be implementing robust output sanitization and securing the shortcode's execution context.
Key Concerns
- Unescaped output
- No capability checks on shortcode
- Flow with unsanitized path
notikumiWP Security Vulnerabilities
notikumiWP Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
notikumiWP Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
notikumiWP Maintenance & Trust
Maintenance Signals
Community Trust
notikumiWP Alternatives
Meetup Events Widget
meetup-events-widget
Este widget muestra los eventos extraídos de meetup.com del país y ciudad que elijamos.
Kultur-API for WordPress
kultur-api-for-wp
Simple integration of your culture database into WordPress
TCultura Connect
tcultura-connect
Display cultural events and activities from the TCultura / DataCultura platform on your WordPress site.
The Events Calendar
the-events-calendar
The Events Calendar: #1 calendar plugin for WordPress. Create/manage events (virtual too!) on your site with the free plugin.
LatePoint – Calendar Booking Plugin for Appointments and Events
latepoint
Optimize your appointment scheduling with our plugin. Sync calendars, automate reminders, and keep your bookings organized.
notikumiWP Developer Profile
3 plugins · 20 total installs
How We Detect notikumiWP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/notikumi/css/styles.css/wp-content/plugins/notikumi/css/colorpicker/css/colorpicker.css/wp-content/plugins/notikumi/js/notikumi_fn_widget.js/wp-content/plugins/notikumi/js/notikumi_init_widget.js/wp-content/plugins/notikumi/js/notikumi_fn_widget.js/wp-content/plugins/notikumi/js/notikumi_init_widget.js/wp-content/plugins/notikumi/js/colorpicker/colorpicker.js/wp-content/plugins/notikumi/js/jquery/jquery.ui.autocomplete.min.jsnotikumi/styles.css?ver=notikumi/css/colorpicker/css/colorpicker.css?ver=notikumi/js/notikumi_fn_widget.js?ver=notikumi/js/notikumi_init_widget.js?ver=notikumi/js/colorpicker/colorpicker.js?ver=notikumi/js/jquery/jquery.ui.autocomplete.min.js?ver=HTML / DOM Fingerprints
<!-- save to options when the form is sent --><!-- si envían formulario --><!-- Tratamiento del formulario enviado --><!-- Calculo de la firma -->+8 morevar NotikumiWPimpl[NTK]