
Private Google Calendars Security & Risk Analysis
wordpress.org/plugins/private-google-calendarsDisplay private and public Google Calendars on your Wordpress website.
Is Private Google Calendars Safe to Use in 2026?
Generally Safe
Score 98/100Private Google Calendars has a strong security track record. Known vulnerabilities have been patched promptly.
The "private-google-calendars" plugin exhibits a mixed security posture. While the static analysis shows a low attack surface with no immediately identified unprotected entry points, and a commendable lack of critical or high-severity taint flows, concerns arise from its past vulnerability history and code hygiene. The plugin has a history of two medium-severity CVEs, one of which was a cross-site scripting vulnerability, indicating potential issues with input sanitization and output escaping. The fact that these were addressed suggests developer responsiveness, but the presence of historical vulnerabilities warrants caution. The code analysis reveals that 100% of SQL queries are not using prepared statements, which is a significant risk for SQL injection vulnerabilities, especially when dealing with user-provided input. Furthermore, only 32% of output escaping is properly handled, increasing the likelihood of cross-site scripting (XSS) vulnerabilities. Despite the positive indicators like the presence of nonce and capability checks, the lack of prepared statements for all SQL queries and the low rate of output escaping are critical weaknesses that outweigh the limited attack surface. Future development should prioritize robust input validation, prepared statements for all database interactions, and comprehensive output escaping.
Key Concerns
- All SQL queries lack prepared statements
- Low output escaping rate (32%)
- Two medium severity vulnerabilities in history
Private Google Calendars Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Private Google Calendars <= 20250811 - Missing Authorization to Authenticated (Subscriber+) Settings Reset
Private Google Calendars <= 20231125 - Authenticated (Contributor+) Stored Cross-Site Scripting
Private Google Calendars Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Private Google Calendars Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 19
Maintenance & Trust
Private Google Calendars Maintenance & Trust
Maintenance Signals
Community Trust
Private Google Calendars Alternatives
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
ICS Calendar
ics-calendar
Add the calendar you already use to Any WordPress site! Google Calendar, Microsoft 365, iCloud and more… no API keys or complicated setup required.
Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar
booking-manager
Showing events listing from .ics feeds or sync bookings from different sources to your website
Pretty Google Calendar
pretty-google-calendar
Embedded Google Calendars that don't suck.
Events Calendar for Google
events-calendar-for-google
Events Calendar for Google implements google calender to your wordpress website using different style and layouts. Get connected to your audience usin …
Private Google Calendars Developer Profile
4 plugins · 1K total installs
How We Detect Private Google Calendars
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/private-google-calendars/css/themes/pgc-dark.css/wp-content/plugins/private-google-calendars/css/themes/pgc-light.css/wp-content/plugins/private-google-calendars/css/themes/pgc-default.cssprivate-google-calendars/css/themes/pgc-dark.css?ver=private-google-calendars/css/themes/pgc-light.css?ver=private-google-calendars/css/themes/pgc-default.css?ver=HTML / DOM Fingerprints
pgc-theme-data-pgc-shortcode-idpgc_google_api_keypgc_optionspgc_default_themepgc_calendarListpgc_block_trans