Plugin name: SFCe Create Event Security & Risk Analysis

wordpress.org/plugins/sfce-create-event

Create Facebook events automatically when you create Wordpress posts. This plugin requires the Simple Facebook Connect plugin by Otto.

10 active installs v4.00.2 PHP + WP 2.7+ Updated Feb 15, 2012
createeventfacebooksfcsimple-facebook-connect
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Plugin name: SFCe Create Event Safe to Use in 2026?

Generally Safe

Score 85/100

Plugin name: SFCe Create Event has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 14yr ago
Risk Assessment

The "sfce-create-event" plugin v4.00.2 exhibits a mixed security posture. On the positive side, it has no known CVEs, a clean vulnerability history, and its SQL queries are correctly prepared. It also incorporates nonce and capability checks on some entry points and avoids bundled libraries. However, significant concerns arise from its output escaping and file operation handling. A complete lack of proper output escaping (0% escapement) across 25 outputs is a critical vulnerability, exposing users to cross-site scripting (XSS) attacks. Additionally, the presence of two flows with unsanitized paths, while not yet classified as critical or high in the taint analysis, indicates a potential for path traversal or other file-related vulnerabilities. The plugin's limited attack surface is a mitigating factor, but the identified weaknesses, particularly in output sanitization, pose a substantial risk.

Key Concerns

  • No output escaping detected
  • Unsanitized paths detected in taint analysis
  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

Plugin name: SFCe Create Event Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Plugin name: SFCe Create Event Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
0 escaped
Nonce Checks
2
Capability Checks
2
File Operations
2
External Requests
3
Bundled Libraries
0

Output Escaping

0% escaped25 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
sfce_get_access_token (sfce-invite-people.php:128)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Plugin name: SFCe Create Event Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actionplugins_loadedsfce-create-event.php:33
actionadmin_menusfce-create-event.php:34
actionadmin_menusfce-settings-page.php:4
actionedit_form_advancedsfce_create_event_post.php:46
actionedit_postsfce_create_event_post.php:48
Maintenance & Trust

Plugin name: SFCe Create Event Maintenance & Trust

Maintenance Signals

WordPress version tested3.3.2
Last updatedFeb 15, 2012
PHP min version
Downloads12K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Plugin name: SFCe Create Event Developer Profile

roggie

3 plugins · 220 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Plugin name: SFCe Create Event

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sfce-create-event/sfce-create-event.php/wp-content/plugins/sfce-create-event/sfce_create_event_post.php/wp-content/plugins/sfce-create-event/sfce-settings-page.php

HTML / DOM Fingerprints

Data Attributes
name="sfce_event_name"name="sfce_event_description"name="sfce_event_host"name="sfce_event_tagline"name="sfce_event_is_fanpage"name="sfce_event_privacy"+4 more
FAQ

Frequently Asked Questions about Plugin name: SFCe Create Event