
Simple Calendar – Advanced Custom Fields Security & Risk Analysis
wordpress.org/plugins/simple-calendar-acfAdd a Simple Calendar field to Advanced Customs Fields (ACF).
Is Simple Calendar – Advanced Custom Fields Safe to Use in 2026?
Generally Safe
Score 85/100Simple Calendar – Advanced Custom Fields has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "simple-calendar-acf" plugin v1.0.2 exhibits a strong security posture based on the provided static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface, with zero unprotected entry points. Furthermore, the code signals indicate a commendable approach to data handling, featuring no dangerous functions, exclusively using prepared statements for SQL queries, and avoiding file operations or external HTTP requests. The taint analysis reporting zero flows with unsanitized paths further reinforces this positive assessment, suggesting no obvious vulnerabilities related to data manipulation.
However, a significant concern arises from the output escaping analysis, where only 25% of outputs are properly escaped. This indicates a potential risk of Cross-Site Scripting (XSS) vulnerabilities, as unsanitized user-supplied data displayed on the frontend could be exploited. Additionally, the complete lack of nonce checks and capability checks, especially given the absence of any entry points that *require* them, suggests that if any entry points were to be introduced in the future, they might be implemented without these crucial security mechanisms. The vulnerability history also shows no recorded CVEs, which is positive but doesn't negate the risks identified in the current static analysis. Overall, while the plugin has a minimal attack surface and handles SQL securely, the output escaping and lack of comprehensive security checks for potential future entry points are areas that require attention.
Key Concerns
- Low output escaping rate
- No nonce checks implemented
- No capability checks implemented
Simple Calendar – Advanced Custom Fields Security Vulnerabilities
Simple Calendar – Advanced Custom Fields Code Analysis
Output Escaping
Simple Calendar – Advanced Custom Fields Attack Surface
WordPress Hooks 5
Maintenance & Trust
Simple Calendar – Advanced Custom Fields Maintenance & Trust
Maintenance Signals
Community Trust
Simple Calendar – Advanced Custom Fields Alternatives
ACF: Google Maps Field (Multiple Markers)
acf-google-map-field-multiple-markers
An advanced Google Maps field for ACF that allows you to add multiple markers/pins to a single map field.
ACF Content Analysis for Yoast SEO
acf-content-analysis-for-yoast-seo
WordPress plugin that adds the content of all ACF fields to the Yoast SEO score analysis.
Advanced Custom Fields: Font Awesome Field
advanced-custom-fields-font-awesome
Adds a new 'Font Awesome Icon' field to the popular Advanced Custom Fields plugin.
Table Field Add-on for ACF and SCF
advanced-custom-fields-table-field
A Table Field Add-on for the Advanced Custom Fields and Secure Custom Fields Plugin.
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
Simple Calendar – Advanced Custom Fields Developer Profile
4 plugins · 51K total installs
How We Detect Simple Calendar – Advanced Custom Fields
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-calendar-acf/includes/acf/field-v4.php/wp-content/plugins/simple-calendar-acf/includes/acf/field-v5.phpHTML / DOM Fingerprints
simcal-field-select-enhanceddata-allow_nullsimcal_admin[calendar id="