
Posts To Events Security & Risk Analysis
wordpress.org/plugins/posts-to-eventsThis is a simple plugin for adding callendar functionality to posts.
Is Posts To Events Safe to Use in 2026?
Generally Safe
Score 85/100Posts To Events has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "posts-to-events" plugin v1.56 exhibits a mixed security posture. On the positive side, the static analysis reveals a very small attack surface with no apparent AJAX handlers, REST API routes, shortcodes, or cron events directly exposed without authentication. This suggests a deliberate effort to limit potential entry points. The presence of nonce and capability checks, although limited in number, is a good practice. However, the code analysis highlights significant concerns regarding the use of dangerous functions like `create_function`, which is known to be a source of vulnerabilities if not handled with extreme care. Furthermore, a low rate of proper output escaping (20%) presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities, as data displayed to users may not be sufficiently sanitized. The taint analysis, while showing no critical or high severity flows, did reveal that all analyzed flows involved unsanitized paths, which, when combined with the poor output escaping, increases the risk. The complete lack of recorded vulnerabilities in its history is a positive indicator, suggesting the plugin has been relatively stable or well-maintained in the past. However, this historical data should not overshadow the identified code-level risks. In conclusion, while the plugin has a small attack surface, the identified use of dangerous functions and a high percentage of improperly escaped output are substantial weaknesses that require attention and mitigation. The absence of historical CVEs is a strength, but the current code analysis points to potential future vulnerabilities.
Key Concerns
- Use of dangerous function `create_function`
- Low output escaping rate (20%)
- All taint flows have unsanitized paths
- SQL queries (33%) without prepared statements
Posts To Events Security Vulnerabilities
Posts To Events Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Posts To Events Attack Surface
WordPress Hooks 12
Maintenance & Trust
Posts To Events Maintenance & Trust
Maintenance Signals
Community Trust
Posts To Events Alternatives
Calendar Posts
calendar-posts
A powerful yet simple plugin for adding calendar functionality to posts. Great for using posts as events and calendar inputs.
Same Category Posts
same-category-posts
Show posts related to the current category or other custom post types.
Schedule Posts Calendar
schedule-posts-calendar
Adds a JavaScript calendar to the scheduled publish widget to allow you to select a date and time graphically instead of via the text entry boxes.
The Future Is Now
the-future-is-now
Allow future-time-stamped posts to appear live on your site immediately.
Blog Post Calendar Widget
blog-post-calendar-widget
The Blog Posts Calendar Widget allows you to display your archived or future posts in a calendar as a sidebar widget.
Posts To Events Developer Profile
1 plugin · 10 total installs
How We Detect Posts To Events
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/posts-to-events/pte_style.css/wp-content/plugins/posts-to-events/script.jsposts-to-events/pte_style.css?ver=posts-to-events/inc/jquery-ui-1.10.2/css/excite-bike/jquery-ui-1.10.2.custom.css?ver=HTML / DOM Fingerprints
DeleteSubmit<!-- #? This file contains the admin panel options --><!-- #? Load widget file --><!-- #? Register the date metabox for all post types--><!-- #? Store date data in post meta table -->+2 morepte_datepte_date_noncepte_date_deletejQuery