Simple Google Calendar Outlook Events Widget Security & Risk Analysis

wordpress.org/plugins/simple-google-icalendar-widget

Block widget that displays events from a public google calendar or iCal file.

1K active installs v3.0.0 PHP 7.4+ WP 5.3+ Updated Jan 9, 2026
blockcalendareventsgoogle-calendarical
99
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 11, 2025
Safety Verdict

Is Simple Google Calendar Outlook Events Widget Safe to Use in 2026?

Generally Safe

Score 99/100

Simple Google Calendar Outlook Events Widget has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Feb 11, 2025Updated 2mo ago
Risk Assessment

The static analysis of simple-google-icalendar-widget v3.0.0 reveals a generally strong security posture. The absence of critical code signals like dangerous functions, raw SQL queries, file operations, and unsanitized taint flows is highly positive. The plugin also demonstrates good output escaping practices, with all 316 outputs being properly escaped. The presence of capability checks indicates an awareness of access control, though the lack of nonce checks on AJAX handlers and REST API routes (which are currently zero) is a potential concern should these entry points be introduced in the future without proper authentication. The plugin does perform external HTTP requests, which, while not inherently a vulnerability, can be a vector if the target API is compromised or if data is not handled securely on return.

The vulnerability history is a mixed bag. While there are no currently unpatched CVEs, the presence of a past medium-severity Cross-site Scripting (XSS) vulnerability, even if patched, suggests that input sanitization might not always be perfect. The fact that the last vulnerability was in the near future (2025-02-11) could indicate a potential data entry error in the provided history or a hypothetical scenario, but assuming it represents a real past event, it reinforces the need for continued vigilance regarding input handling.

In conclusion, simple-google-icalendar-widget v3.0.0 has implemented several key security best practices, particularly in code sanitization and output handling. However, the absence of nonce checks on the (currently empty) AJAX and REST API routes, along with the history of an XSS vulnerability, highlights areas where future development or updates should maintain a high level of scrutiny. The overall risk is moderate, leaning towards low due to the lack of active vulnerabilities and the positive static analysis findings.

Key Concerns

  • Past medium XSS vulnerability requires input validation vigilance
  • No nonce checks on AJAX/REST API routes (currently 0)
Vulnerabilities
1

Simple Google Calendar Outlook Events Widget Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-22497medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Simple Google Calendar Outlook Events Block Widget <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Feb 11, 2025 Patched in 2.6.0 (24d)
Code Analysis
Analyzed Mar 16, 2026

Simple Google Calendar Outlook Events Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
316 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped316 total outputs
Attack Surface

Simple Google Calendar Outlook Events Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionwp_enqueue_scriptssimple-google-icalendar-widget.php:75
actionwp_enqueue_scriptssimple-google-icalendar-widget.php:77
actionenqueue_block_assetssimple-google-icalendar-widget.php:80
actionadmin_initsimple-google-icalendar-widget.php:84
actionadmin_menusimple-google-icalendar-widget.php:85
actionadmin_menusimple-google-icalendar-widget.php:86
actionwidgets_initsimple-google-icalendar-widget.php:121
Maintenance & Trust

Simple Google Calendar Outlook Events Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 9, 2026
PHP min version7.4
Downloads32K

Community Trust

Rating100/100
Number of ratings6
Active installs1K
Developer Profile

Simple Google Calendar Outlook Events Widget Developer Profile

bramwaas

1 plugin · 1K total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
24 days
View full developer profile
Detection Fingerprints

How We Detect Simple Google Calendar Outlook Events Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/simple-google-icalendar-widget/js/simple-ical-block-view.js/wp-content/plugins/simple-google-icalendar-widget/vendor/bs/js/collapse.bundle.js/wp-content/plugins/simple-google-icalendar-widget/vendor/bs/css/collapse.css
Version Parameters
simple-google-icalendar-widget/js/simple-ical-block-view.js?ver=simple-google-icalendar-widget/vendor/bs/js/collapse.bundle.js?ver=simple-google-icalendar-widget/vendor/bs/css/collapse.css?ver=

HTML / DOM Fingerprints

Data Attributes
simple_ical_block_attrs
JS Globals
window.simpleIcalBlock
REST Endpoints
/wp-json/waasdorp-soekhan-wp-plugin-simple-google-icalendar-widget/v1/get_content_by_ids
FAQ

Frequently Asked Questions about Simple Google Calendar Outlook Events Widget