Now Showing at Local Venues – Nearby Upcoming Events Security & Risk Analysis

wordpress.org/plugins/now-showing-at-local-venues

Now Showing at Local Venues displays a slideshow of upcoming events w/ photos & details for any location. Just type in your location and show even …

10 active installs v1.0.2 PHP + WP 2.0.2+ Updated Sep 14, 2012
eventslocalnearbyupcomingvenues
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Now Showing at Local Venues – Nearby Upcoming Events Safe to Use in 2026?

Generally Safe

Score 85/100

Now Showing at Local Venues – Nearby Upcoming Events has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 13yr ago
Risk Assessment

The "now-showing-at-local-venues" plugin version 1.0.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all its SQL queries and correctly implementing capability checks for its single entry point (a shortcode). The absence of known CVEs and a clean vulnerability history further contribute to a relatively low perceived risk. However, significant concerns arise from the complete lack of output escaping for all 12 detected output points. This is a critical weakness that could lead to cross-site scripting (XSS) vulnerabilities if any user-supplied data is reflected without sanitization. Additionally, the absence of nonce checks is a notable omission, especially given the presence of one file operation, which could potentially be exploited in certain scenarios. While the attack surface is small and the entry point is protected by capability checks, the lack of output escaping is a serious oversight that attackers could leverage.

The plugin's vulnerability history is clean, which is a strong indicator of past security diligence. However, this does not negate the immediate risks identified in the static analysis. The strengths lie in its structured database interactions and permission checks. The primary weakness is the broad lack of output escaping, a fundamental security control that has been overlooked. While taint analysis found no issues, this is likely due to the limited number of flows analyzed and does not guarantee the absence of vulnerabilities. In conclusion, while the plugin has a clean history and handles database interactions securely, the complete absence of output escaping presents a substantial risk of XSS vulnerabilities that requires immediate attention.

Key Concerns

  • All outputs unescaped
  • No nonce checks for entry points
Vulnerabilities
None known

Now Showing at Local Venues – Nearby Upcoming Events Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Now Showing at Local Venues – Nearby Upcoming Events Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped12 total outputs
Attack Surface

Now Showing at Local Venues – Nearby Upcoming Events Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[nearby-events] nearby-upcoming-events.php:409
WordPress Hooks 4
actionwp_enqueue_scriptsnearby-upcoming-events.php:34
actionadmin_initnearby-upcoming-events.php:70
actionadmin_menunearby-upcoming-events.php:126
filterwidget_textnearby-upcoming-events.php:410
Maintenance & Trust

Now Showing at Local Venues – Nearby Upcoming Events Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedSep 14, 2012
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Now Showing at Local Venues – Nearby Upcoming Events Developer Profile

Josh Davis

5 plugins · 860 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Now Showing at Local Venues – Nearby Upcoming Events

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/now-showing-at-local-venues/style.css
Version Parameters
now-showing-at-local-venues/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
wrapfieldsetlegendredentryfieldleftmarleft
Data Attributes
name="nue_keywords"id="nue_keywords"name="nue_location"id="nue_location"name="nue_within"id="nue_within"+16 more
Shortcode Output
[nearby-events keyword="[nearby-events location="[nearby-events within="[nearby-events date="
FAQ

Frequently Asked Questions about Now Showing at Local Venues – Nearby Upcoming Events