
Plugin name: SFCe Create Event Security & Risk Analysis
wordpress.org/plugins/sfce-create-eventCreate Facebook events automatically when you create Wordpress posts. This plugin requires the Simple Facebook Connect plugin by Otto.
Is Plugin name: SFCe Create Event Safe to Use in 2026?
Generally Safe
Score 85/100Plugin name: SFCe Create Event has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "sfce-create-event" plugin v4.00.2 exhibits a mixed security posture. On the positive side, it has no known CVEs, a clean vulnerability history, and its SQL queries are correctly prepared. It also incorporates nonce and capability checks on some entry points and avoids bundled libraries. However, significant concerns arise from its output escaping and file operation handling. A complete lack of proper output escaping (0% escapement) across 25 outputs is a critical vulnerability, exposing users to cross-site scripting (XSS) attacks. Additionally, the presence of two flows with unsanitized paths, while not yet classified as critical or high in the taint analysis, indicates a potential for path traversal or other file-related vulnerabilities. The plugin's limited attack surface is a mitigating factor, but the identified weaknesses, particularly in output sanitization, pose a substantial risk.
Key Concerns
- No output escaping detected
- Unsanitized paths detected in taint analysis
- File operations present
- External HTTP requests present
Plugin name: SFCe Create Event Security Vulnerabilities
Plugin name: SFCe Create Event Code Analysis
Output Escaping
Data Flow Analysis
Plugin name: SFCe Create Event Attack Surface
WordPress Hooks 5
Maintenance & Trust
Plugin name: SFCe Create Event Maintenance & Trust
Maintenance Signals
Community Trust
Plugin name: SFCe Create Event Alternatives
Import Social Events
import-facebook-events
Import Facebook events into your WordPress website and/or Event Calendar. Nice Display with shortcode & Event widget.
WP Event Aggregator: Import Eventbrite events, Meetup events, social events and any iCal Events into Event Calendar
wp-event-aggregator
Xylus WP Event Aggregator: Easy way to import Eventbrite events, MeetUp events, Social site Events into your WordPress Event Calendar.
XT Event Widget for Social Events
xt-facebook-events
Easiest way to display Facebook events from your Facebook page to your website using widget or shortcode.
Tracking Pixel for Gravity Forms
gf-facebook-pixel-tracking
This plugin provides an easy way to add Facebook event tracking to your Gravity Forms using Facebook’s Tracking Pixel. This flexible plugin works for …
My Agile Pixel – The GDPR Analytics and Tracking Pixel Solution
myagilepixel
Avoid legal issues with Google Analytics, Facebook Pixel, and TikTok Pixel. Boost marketing with custom user properties in Google Analytics 4.
Plugin name: SFCe Create Event Developer Profile
3 plugins · 220 total installs
How We Detect Plugin name: SFCe Create Event
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sfce-create-event/sfce-create-event.php/wp-content/plugins/sfce-create-event/sfce_create_event_post.php/wp-content/plugins/sfce-create-event/sfce-settings-page.phpHTML / DOM Fingerprints
name="sfce_event_name"name="sfce_event_description"name="sfce_event_host"name="sfce_event_tagline"name="sfce_event_is_fanpage"name="sfce_event_privacy"+4 more