
Now Showing at Local Venues – Nearby Upcoming Events Security & Risk Analysis
wordpress.org/plugins/now-showing-at-local-venuesNow Showing at Local Venues displays a slideshow of upcoming events w/ photos & details for any location. Just type in your location and show even …
Is Now Showing at Local Venues – Nearby Upcoming Events Safe to Use in 2026?
Generally Safe
Score 85/100Now Showing at Local Venues – Nearby Upcoming Events has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "now-showing-at-local-venues" plugin version 1.0.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all its SQL queries and correctly implementing capability checks for its single entry point (a shortcode). The absence of known CVEs and a clean vulnerability history further contribute to a relatively low perceived risk. However, significant concerns arise from the complete lack of output escaping for all 12 detected output points. This is a critical weakness that could lead to cross-site scripting (XSS) vulnerabilities if any user-supplied data is reflected without sanitization. Additionally, the absence of nonce checks is a notable omission, especially given the presence of one file operation, which could potentially be exploited in certain scenarios. While the attack surface is small and the entry point is protected by capability checks, the lack of output escaping is a serious oversight that attackers could leverage.
The plugin's vulnerability history is clean, which is a strong indicator of past security diligence. However, this does not negate the immediate risks identified in the static analysis. The strengths lie in its structured database interactions and permission checks. The primary weakness is the broad lack of output escaping, a fundamental security control that has been overlooked. While taint analysis found no issues, this is likely due to the limited number of flows analyzed and does not guarantee the absence of vulnerabilities. In conclusion, while the plugin has a clean history and handles database interactions securely, the complete absence of output escaping presents a substantial risk of XSS vulnerabilities that requires immediate attention.
Key Concerns
- All outputs unescaped
- No nonce checks for entry points
Now Showing at Local Venues – Nearby Upcoming Events Security Vulnerabilities
Now Showing at Local Venues – Nearby Upcoming Events Code Analysis
Output Escaping
Now Showing at Local Venues – Nearby Upcoming Events Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Now Showing at Local Venues – Nearby Upcoming Events Maintenance & Trust
Maintenance Signals
Community Trust
Now Showing at Local Venues – Nearby Upcoming Events Alternatives
Upcoming Events Lists
upcoming-events-lists
A WordPress plugin to show a list of upcoming events on the front-end.
Nearby Map by Wabeo
nearby-map
Allow you to insert a map to show activities, places and services around a given geographical point.
Events Listing Widget
events-listing-widget
Create a list of upcoming events and display them using an easy-to-use widget
External Events Calendar
external-events-calendar
This plugin adds a basic "upcoming events" calendar of links to Wordpress.
Localist Calendar for WordPress
localist-calendar
The most powerful way to highlight events on your WordPress website.
Now Showing at Local Venues – Nearby Upcoming Events Developer Profile
5 plugins · 860 total installs
How We Detect Now Showing at Local Venues – Nearby Upcoming Events
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/now-showing-at-local-venues/style.cssnow-showing-at-local-venues/style.css?ver=HTML / DOM Fingerprints
wrapfieldsetlegendredentryfieldleftmarleftname="nue_keywords"id="nue_keywords"name="nue_location"id="nue_location"name="nue_within"id="nue_within"+16 more[nearby-events keyword="[nearby-events location="[nearby-events within="[nearby-events date="