
Scroll Widget for EventPrime Security & Risk Analysis
wordpress.org/plugins/scroll-widget-for-eventprimeThis plugin generates links from posts of the official EventPrime plugin :raised_hands: with a specific post_type and displays them in a scrolling wid …
Is Scroll Widget for EventPrime Safe to Use in 2026?
Generally Safe
Score 85/100Scroll Widget for EventPrime has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The scroll-widget-for-eventprime plugin v1.6.1 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and a clean vulnerability history suggest a well-maintained and secure plugin. The code analysis reveals no dangerous functions, SQL injection risks (all queries use prepared statements), file operations, or external HTTP requests. Furthermore, there are no observed taint flows with unsanitized paths, indicating a low risk of common injection vulnerabilities.
However, there are areas that warrant attention. While the attack surface is small with only one shortcode and no unprotected entry points, the complete lack of nonce checks and capability checks across all entry points is a significant concern. This means that even if the entry points are not directly exposed via AJAX or REST API without authentication, any logic within the shortcode could potentially be triggered by an authenticated user in unexpected ways or without proper user consent. The 15% of improperly escaped outputs also present a potential cross-site scripting (XSS) risk, albeit likely a minor one given the limited attack surface and the overall lack of other exploitable findings.
In conclusion, the plugin is commendably free of critical vulnerabilities and demonstrates good coding practices in many areas. The primary weaknesses lie in the absence of robust authorization checks (capability checks and nonces) and some minor output escaping issues. These are important considerations for a comprehensive security assessment, even in the absence of active exploits.
Key Concerns
- Lack of nonce checks
- Lack of capability checks
- Improperly escaped output (15%)
Scroll Widget for EventPrime Security Vulnerabilities
Scroll Widget for EventPrime Release Timeline
Scroll Widget for EventPrime Code Analysis
Output Escaping
Scroll Widget for EventPrime Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
Scroll Widget for EventPrime Maintenance & Trust
Maintenance Signals
Community Trust
Scroll Widget for EventPrime Alternatives
Anton Featured Events Manager
4nton-featured-events-manager
Anton Featured Events Manager is an addons of Events Manager created By Marcus Sykes.
LCS Fast Calendar Widget for Events Manager
lcs-em-widget-calendar
This plugin adds a fast sidebar calendar widget to replace the one that comes with Events Manager.
Lightweight Sidebar Manager
sidebar-manager
Create new sidebar areas and display them conditionally on certain pages. Works with all themes.
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
My Calendar – Accessible Event Manager
my-calendar
Accessible WordPress event calendar plugin. Manage single or recurring events, event venues, and display your calendar anywhere on your site.
Scroll Widget for EventPrime Developer Profile
2 plugins · 10 total installs
How We Detect Scroll Widget for EventPrime
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scroll-widget-for-eventprime/assets/js/scroll-widget-for-eventprime.js/wp-content/plugins/scroll-widget-for-eventprime/assets/css/scroll-widget-for-eventprime.css/wp-content/plugins/scroll-widget-for-eventprime/assets/js/scroll-widget-for-eventprime.jsscroll-widget-for-eventprime/assets/js/scroll-widget-for-eventprime.js?ver=scroll-widget-for-eventprime/assets/css/scroll-widget-for-eventprime.css?ver=HTML / DOM Fingerprints
sw_so_widget-outer-containersw_so_widget-featuredsw_so_widget-containersw_so_widget-linkssw_so_widget-linksw_so_widget-event-magic-not-installedname="sw_so_scroll_plugin_options[label]"name="sw_so_scroll_plugin_options[posttype]"name="sw_so_scroll_plugin_options[timeOut]"name="sw_so_scroll_plugin_options[interVal]"id="label"id="posttype"+2 more[sw_for_eventprime]