
RSVPMaker Security & Risk Analysis
wordpress.org/plugins/rsvpmakerEvent and email marketing. Register guests and collect payment by PayPal or Stripe. Send invitations and newsletters.
Is RSVPMaker Safe to Use in 2026?
Mostly Safe
Score 81/100RSVPMaker is generally safe to use. 17 past CVEs were resolved. Keep it updated.
The rsvpmaker plugin exhibits a mixed security posture. While it employs numerous nonces and capability checks, and the vast majority of its SQL queries use prepared statements, significant concerns arise from its attack surface and taint analysis. The presence of 5 unprotected AJAX handlers creates a substantial entry point for unauthorized actions. The high number of flows with unsanitized paths, including 29 critical taint flows, strongly suggests the potential for severe vulnerabilities like Cross-Site Scripting (XSS) and Server-Side Request Forgery (SSRF) if input is not rigorously validated and sanitized before use. The plugin's historical vulnerability record is concerning, with a significant number of past critical and high-severity CVEs, including issues related to deserialization, SQL injection, and XSS. The fact that the last known vulnerability was very recent (2025-05-19) indicates a recurring need for security diligence. The bundling of libraries like Guzzle and Stripe PHP also presents a potential risk if these are not kept up-to-date, though their specific version status isn't provided.
In conclusion, while some security best practices are in place, the combination of a large unprotected attack surface, critical taint flows indicating potential code execution or data leakage risks, and a history of severe vulnerabilities necessitates a cautious approach. The plugin has demonstrated weaknesses in input sanitization and authorization, which have led to critical security issues in the past. Aggressive patching and remediation of the identified taint flows and unprotected AJAX endpoints are strongly recommended.
Key Concerns
- Unprotected AJAX handlers
- Critical severity taint flows
- High severity taint flows
- Unsanitized paths in taint analysis
- Critical historical CVEs
- High historical CVEs
- Deserialization of Untrusted Data history
- Cross-Site Scripting history
- SQL Injection history
- Server-Side Request Forgery history
- Dangerous functions (unserialize, passthru)
- Low output escaping percentage
RSVPMaker Security Vulnerabilities
CVEs by Year
Severity Breakdown
17 total CVEs
RSVPMarker <= 11.5.6 - Authenticated (Contributor+) SQL Injection
RSVPMarker <= 11.6.7 - Unauthenticated SQL Injection
RSVPMarker <= 11.4.5 - Missing Authorization
RSVPMaker <= 10.6.6 - Unauthenticated PHP Object Injection
RSVPMarker <= 10.6.6 - Unauthenticated SQL Injection
RSVPMaker <= 10.6.5 - Unauthenticated Stored Cross-Site Scripting via 'email'
RSVPMarker <= 10.6.5 - Authenticated (Administrator+) Stored Cross-Site Scripting via admin settings
RSVPMaker <= 10.5.4 - Authenticated (Administrator+) SQL Injection via 'resend'
RSVPMaker <= 9.9.3 - Authenticated (Admin+) SQL Injection via 'delete' parameter
RSVPMaker <= 9.9.3 - Authenticated (Admin+) SQL Injection via $email value
RSVPMaker <= 9.3.2 - Unauthenticated SQL Injection
RSVPMaker <= 9.2.6 - Unauthenticated SQL Injection
RSVPMaker <= 9.2.5 - Unauthenticated SQL Injection
RSVPMaker <= 8.7.2 - Server-Side Request Forgery
RSVPMaker <= 7.8.1 - Unauthenticated SQL Injection via 'event_count'
RSVPMaker <= 6.1.9 - SQL Injection
RSVPMaker < 5.6.4 - SQL Injection
RSVPMaker Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
RSVPMaker Attack Surface
AJAX Handlers 5
Shortcodes 54
WordPress Hooks 217
Scheduled Events 27
Maintenance & Trust
RSVPMaker Maintenance & Trust
Maintenance Signals
Community Trust
RSVPMaker Alternatives
Registrations for the Events Calendar – Event Registration Plugin
registrations-for-the-events-calendar
Collect and manage event registrations with a customizable form and email template. The best event registration plugin for The Events Calendar.
Add to Calendar Button
add-to-calendar-button
Create beautiful buttons, where people can add events to their calendars. Highly customizable. As shortcode or via a convenient block.
RSVP and Event Management
rsvp
Simple Event Registration & RSVP Management for WordPress
Events Maker by dFactory
events-maker
Fully featured event management system including recurring events, locations management, full calendar, iCal feed/files, google maps and more.
GreenRope Analytics
greenrope-analytics
Enables you to add GreenRope analytics and tracking to every page of your WordPress site.
RSVPMaker Developer Profile
10 plugins · 490 total installs
How We Detect RSVPMaker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rsvpmaker/rsvpmaker.css/wp-content/plugins/rsvpmaker/js/rsvpmaker-public.js/wp-content/plugins/rsvpmaker/js/rsvpmaker-admin.js/wp-content/plugins/rsvpmaker/css/rsvpmaker-admin.css/wp-content/plugins/rsvpmaker/js/rsvpmaker-public.js/wp-content/plugins/rsvpmaker/js/rsvpmaker-admin.jsrsvpmaker.css?ver=rsvpmaker-public.js?ver=rsvpmaker-admin.js?ver=rsvpmaker-admin.css?ver=HTML / DOM Fingerprints
rsvpmakerrsvp-form-sectionrsvp-confirmation-messagersvpmaker_attendee_listrsvpmaker-attendees<!-- wp:rsvpmaker/formfield<!-- wp:rsvpmaker/guests<!-- wp:rsvpmaker/formnote<!-- /wp:rsvpmaker/formfield+2 moredata-rsvpmaker-post-iddata-rsvpmaker-event-slugdata-rsvpmaker-noncersvpmaker_ajax_objectRSVPmakerPublicRSVPmakerAdmin/wp-json/rsvpmaker/v1/submit/wp-json/rsvpmaker/v1/event/wp-json/rsvpmaker/v1/payment[rsvpfield[rsvpprofiletable[rsvpguests[rsvpnote]