
Registrations for the Events Calendar – Event Registration Plugin Security & Risk Analysis
wordpress.org/plugins/registrations-for-the-events-calendarCollect and manage event registrations with a customizable form and email template. The best event registration plugin for The Events Calendar.
Is Registrations for the Events Calendar – Event Registration Plugin Safe to Use in 2026?
Generally Safe
Score 89/100Registrations for the Events Calendar – Event Registration Plugin has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'registrations-for-the-events-calendar' plugin v2.13.10 exhibits a mixed security posture. While it demonstrates a relatively high percentage of SQL prepared statements and output escaping, significant concerns are raised by the static analysis results. The presence of 9 unprotected AJAX handlers out of a total of 22 entry points represents a considerable attack surface that could be exploited by unauthenticated users. Furthermore, the taint analysis revealed 8 high-severity flows with unsanitized paths, indicating potential vulnerabilities where user input might not be properly validated or neutralized before being used in sensitive operations.
The vulnerability history of this plugin is a major red flag, with 7 known CVEs, including 2 critical and 1 high severity. The common vulnerability types (Missing Authorization, SQL Injection, XSS) directly correlate with the findings in the static analysis, particularly the unprotected AJAX endpoints and the potential for unsanitized data flows. The fact that there are currently no unpatched CVEs is a positive sign, but the recurring nature of these vulnerability types suggests a systemic issue in secure coding practices. Ultimately, while the plugin shows some good practices, the high number of unprotected entry points, critical taint flows, and a history of severe vulnerabilities necessitate caution.
Key Concerns
- Unprotected AJAX handlers
- High severity unsanitized taint flows
- History of critical CVEs
- History of high severity CVEs
- History of medium severity CVEs
- Total unprotected entry points
Registrations for the Events Calendar – Event Registration Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
7 total CVEs
Registrations for the Events Calendar <= 2.13.2 - Authenticated (Admin+) Stored Cross-Site Scripting
Registrations for the Events Calendar – Event Registration Plugin <= 2.12.3 - Unauthenticated Stored Cross-Site Scripting
Registrations for the Events Calendar <= 2.12.1 - Missing Authorization
Registrations for the Events Calendar – Event Registration Plugin <= 2.12.2 - Authenticated (Contributor+) SQL Injection
Registrations for the Events Calendar <= 2.7.9 - Reflected Cross-Site Scripting
Registrations for the Events Calendar <= 2.7.5 - Unauthenticated SQL Injection
Registrations for The Events Calendar <= 2.7.4 - Reflected Cross-Site Scripting
Registrations for the Events Calendar – Event Registration Plugin Release Timeline
Registrations for the Events Calendar – Event Registration Plugin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Registrations for the Events Calendar – Event Registration Plugin Attack Surface
AJAX Handlers 22
Shortcodes 2
WordPress Hooks 62
Maintenance & Trust
Registrations for the Events Calendar – Event Registration Plugin Maintenance & Trust
Maintenance Signals
Community Trust
Registrations for the Events Calendar – Event Registration Plugin Alternatives
Event Genius – Event Management, Registration, RSVP, and Tickets
event-genius
Event management plugin for WordPress with built-in registrations, recurring events, tickets, and calendars. Reliable and complete.
Stripe Gateway for Events Manager Pro
stripe-gateway-for-events-manager-pro
A Stripe Gateway for Events Manager Pro plugin.
Events Calendar GForms Registration
ecgf-registration
Use Gravity Forms to handle registration for The Events Calendar events.
Event RSVP and Simple Event Management Plugin
wp-easy-events
Event management, RSVP and event tickets system with event calendar, event venues with maps and event organizers.
Events Handler – The Events Plugin
events-handler
Events Handler enables to manage events and future happenings and show them on your wordpress site.
Registrations for the Events Calendar – Event Registration Plugin Developer Profile
1 plugin · 7K total installs
How We Detect Registrations for the Events Calendar – Event Registration Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/registrations-for-the-events-calendar/inc/blocks/css/frontend.css/wp-content/plugins/registrations-for-the-events-calendar/inc/blocks/css/frontend.min.css/wp-content/plugins/registrations-for-the-events-calendar/assets/css/frontend.css/wp-content/plugins/registrations-for-the-events-calendar/assets/css/frontend.min.css/wp-content/plugins/registrations-for-the-events-calendar/assets/js/frontend.js/wp-content/plugins/registrations-for-the-events-calendar/assets/js/frontend.min.js/wp-content/plugins/registrations-for-the-events-calendar/assets/js/register-script.js/wp-content/plugins/registrations-for-the-events-calendar/assets/js/register-script.min.js+4 more/wp-content/plugins/registrations-for-the-events-calendar/inc/blocks/css/frontend.css/wp-content/plugins/registrations-for-the-events-calendar/inc/blocks/css/frontend.min.css/wp-content/plugins/registrations-for-the-events-calendar/assets/css/frontend.css/wp-content/plugins/registrations-for-the-events-calendar/assets/css/frontend.min.css/wp-content/plugins/registrations-for-the-events-calendar/assets/js/frontend.js/wp-content/plugins/registrations-for-the-events-calendar/assets/js/frontend.min.js+6 more/wp-content/plugins/registrations-for-the-events-calendar/assets/css/frontend.css?ver=/wp-content/plugins/registrations-for-the-events-calendar/assets/js/frontend.js?ver=/wp-content/plugins/registrations-for-the-events-calendar/assets/js/register-script.js?ver=/wp-content/plugins/registrations-for-the-events-calendar/assets/js/registration-form.js?ver=/wp-content/plugins/registrations-for-the-events-calendar/assets/js/admin.js?ver=HTML / DOM Fingerprints
rtec-registration-formrtec-registration-sectionrtec-frontend-submissionrtec-frontend-event-registration<!-- RTEC_FORM_START --><!-- RTEC_FORM_END --><!-- START RTEC FRONTEND EVENT REGISTRATION --><!-- END RTEC FRONTEND EVENT REGISTRATION -->data-rtec-post-idRTEC_FRONTENDRTEC_SETTINGS/wp-json/rtec/v1/registrations[rtec-registration-form][rtec_registration_form]