
Schedule Builder Online Security & Risk Analysis
wordpress.org/plugins/schedule-builder-onlineCreate stunning schedules and share them by easily embedding them directly into your posts/pages of your blog/website.
Is Schedule Builder Online Safe to Use in 2026?
Generally Safe
Score 85/100Schedule Builder Online has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "schedule-builder-online" v1.0.1 plugin presents a generally secure initial posture, with a clean vulnerability history and no critical or high-severity code signals detected. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the plugin utilizes prepared statements for its SQL queries, which is a strong defense against SQL injection vulnerabilities. The presence of nonce checks on at least one entry point is also a positive indicator of security awareness.
However, a significant concern arises from the complete lack of output escaping on all identified output points. This represents a critical weakness, as it leaves the plugin vulnerable to Cross-Site Scripting (XSS) attacks. Any data displayed to users, whether user-supplied or not, could potentially be injected with malicious scripts, compromising user sessions and data. The absence of capability checks on entry points, though not inherently a direct vulnerability without exploitable code, is a missed opportunity to enforce granular access control, potentially broadening the impact if other vulnerabilities were to be discovered.
Given the clean historical vulnerability data, it suggests that developers have been diligent in the past. However, the current static analysis reveals a significant oversight in output sanitization. While the plugin avoids common pitfalls like raw SQL and dangerous functions, the lack of output escaping is a severe and exploitable flaw that demands immediate attention. The overall security is therefore a mix of good practices and a critical oversight in XSS prevention.
Key Concerns
- All identified outputs lack proper escaping
- No capability checks on entry points
Schedule Builder Online Security Vulnerabilities
Schedule Builder Online Code Analysis
Output Escaping
Schedule Builder Online Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Schedule Builder Online Maintenance & Trust
Maintenance Signals
Community Trust
Schedule Builder Online Alternatives
Timetable and Event Schedule by MotoPress
mp-timetable
Smart event organizer and time-management tool with a clean minimalist design for featuring your timetables and upcoming events.
Kenzap Timetable
kenzap-timetable
A beautiful and easy customizable set of Gutenberg blocks to create timetable, school calendars, publish lessons online or create timeline or yoga cou …
UORS External Course List
uors-external-course-list
This plugin adds a "Quick Reserve" widget to your wordpress weblog sidebar. With this widget you can display a list of services that you pr …
Timetable
plan-lekcji
A WordPress plugin for managing school timetables based on files generated by Vulcan Optivum, allowing ZIP file uploads.
The Events Calendar
the-events-calendar
The Events Calendar: #1 calendar plugin for WordPress. Create/manage events (virtual too!) on your site with the free plugin.
Schedule Builder Online Developer Profile
1 plugin · 10 total installs
How We Detect Schedule Builder Online
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/schedule-builder-online/public/css/style.min.css/wp-content/plugins/schedule-builder-online/public/js/main.min.js/wp-content/plugins/schedule-builder-online/admin/js/admin.jshttps://code.jquery.com/jquery-3.3.1.min.jshttps://code.jquery.com/ui/1.12.1/jquery-ui.min.jshttps://cdn.jsdelivr.net/npm/moment/min/moment.min.jsschedule-builder-online/public/css/style.min.css?ver=schedule-builder-online/public/js/main.min.js?ver=schedule-builder-online/admin/js/admin.js?ver=HTML / DOM Fingerprints
schedulebuilderonline-admin-formschedulebuilderonline-admin-saveid="schedulebuilderonline-admin-form"id="schedulebuilderonline_language"id="schedulebuilderonline_size"id="schedulebuilderonline_link"id="schedulebuilderonline_visibility"id="schedulebuilderonline-admin-save"schedulebuilderonline_exchanger[sbo]