
RSVPMaker Widget Security & Risk Analysis
wordpress.org/plugins/rsvpmaker-widgetFetch and display event listings managed via the RSVPMaker plugin on a remote site.
Is RSVPMaker Widget Safe to Use in 2026?
Generally Safe
Score 85/100RSVPMaker Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of rsvpmaker-widget v1.1 reveals a very limited attack surface, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. The absence of dangerous functions, file operations, and external HTTP requests, combined with 100% of SQL queries utilizing prepared statements, suggests a foundational level of good security practices in these areas.
However, a significant concern arises from the low percentage of properly escaped output (3%). This indicates a high likelihood of cross-site scripting (XSS) vulnerabilities, as user-supplied or dynamic data is likely being rendered directly into the page without adequate sanitization. The lack of nonce checks and capability checks further exacerbates this risk, as there are no inherent protections against unauthorized actions or replay attacks should an entry point exist that was not detected. The vulnerability history being completely clear is a positive sign, but it cannot fully mitigate the risks presented by the code analysis, particularly the poor output escaping.
Overall, while the plugin appears to have a small attack surface and employs prepared statements for SQL, the critical deficiency in output escaping presents a substantial risk of XSS. The absence of other common security checks, like nonces and capability checks, means that even minor vulnerabilities could have significant impacts. The clean vulnerability history is encouraging, but it is crucial to address the immediate code-level risks.
Key Concerns
- Low output escaping percentage
- Missing nonce checks
- Missing capability checks
RSVPMaker Widget Security Vulnerabilities
RSVPMaker Widget Code Analysis
Output Escaping
RSVPMaker Widget Attack Surface
WordPress Hooks 5
Maintenance & Trust
RSVPMaker Widget Maintenance & Trust
Maintenance Signals
Community Trust
RSVPMaker Widget Alternatives
Add to Calendar Button
add-to-calendar-button
Create beautiful buttons, where people can add events to their calendars. Highly customizable. As shortcode or via a convenient block.
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
Events Widgets For Elementor And The Events Calendar
events-widgets-for-elementor-and-the-events-calendar
The Events Calendar Elementor widgets help you manage and display an upcoming events list with date, time, venue and event ticket booking details.
Registrations for the Events Calendar – Event Registration Plugin
registrations-for-the-events-calendar
Collect and manage event registrations with a customizable form and email template. The best event registration plugin for The Events Calendar.
RSVP and Event Management
rsvp
Simple Event Registration & RSVP Management for WordPress
RSVPMaker Widget Developer Profile
10 plugins · 490 total installs
How We Detect RSVPMaker Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rsvpmaker-by-json-widget/rsvp-json.js/wp-content/plugins/rsvpmaker-by-json-widget/rsvp-json.jsHTML / DOM Fingerprints
rsvpjsonwidget-id="rsvpjsonwidget-RSVPJsonWidget/wp-json/rsvpmaker/v1/future/wp-json/rsvpmaker/v1/type/featured<div id="rsvpjsonwidget-