
Simple Google Calendar Outlook Events Widget Security & Risk Analysis
wordpress.org/plugins/simple-google-icalendar-widgetBlock widget that displays events from a public google calendar or iCal file.
Is Simple Google Calendar Outlook Events Widget Safe to Use in 2026?
Generally Safe
Score 99/100Simple Google Calendar Outlook Events Widget has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of simple-google-icalendar-widget v3.0.0 reveals a generally strong security posture. The absence of critical code signals like dangerous functions, raw SQL queries, file operations, and unsanitized taint flows is highly positive. The plugin also demonstrates good output escaping practices, with all 316 outputs being properly escaped. The presence of capability checks indicates an awareness of access control, though the lack of nonce checks on AJAX handlers and REST API routes (which are currently zero) is a potential concern should these entry points be introduced in the future without proper authentication. The plugin does perform external HTTP requests, which, while not inherently a vulnerability, can be a vector if the target API is compromised or if data is not handled securely on return.
The vulnerability history is a mixed bag. While there are no currently unpatched CVEs, the presence of a past medium-severity Cross-site Scripting (XSS) vulnerability, even if patched, suggests that input sanitization might not always be perfect. The fact that the last vulnerability was in the near future (2025-02-11) could indicate a potential data entry error in the provided history or a hypothetical scenario, but assuming it represents a real past event, it reinforces the need for continued vigilance regarding input handling.
In conclusion, simple-google-icalendar-widget v3.0.0 has implemented several key security best practices, particularly in code sanitization and output handling. However, the absence of nonce checks on the (currently empty) AJAX and REST API routes, along with the history of an XSS vulnerability, highlights areas where future development or updates should maintain a high level of scrutiny. The overall risk is moderate, leaning towards low due to the lack of active vulnerabilities and the positive static analysis findings.
Key Concerns
- Past medium XSS vulnerability requires input validation vigilance
- No nonce checks on AJAX/REST API routes (currently 0)
Simple Google Calendar Outlook Events Widget Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Simple Google Calendar Outlook Events Block Widget <= 2.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Simple Google Calendar Outlook Events Widget Code Analysis
Output Escaping
Simple Google Calendar Outlook Events Widget Attack Surface
WordPress Hooks 7
Maintenance & Trust
Simple Google Calendar Outlook Events Widget Maintenance & Trust
Maintenance Signals
Community Trust
Simple Google Calendar Outlook Events Widget Alternatives
ICS Calendar
ics-calendar
Add the calendar you already use to Any WordPress site! Google Calendar, Microsoft 365, iCloud and more… no API keys or complicated setup required.
Booking Manager – Sync WP Booking Calendar – Import Events, Export Bookings to ICS Calendar
booking-manager
Showing events listing from .ics feeds or sync bookings from different sources to your website
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
Events Block For The Events Calendar
events-block-for-the-events-calendar
The Events Block for The Events Calendar lets you showcase your events from The Events Calendar right within the Gutenberg pages.
Events Calendar for Google
events-calendar-for-google
Events Calendar for Google implements google calender to your wordpress website using different style and layouts. Get connected to your audience usin …
Simple Google Calendar Outlook Events Widget Developer Profile
1 plugin · 1K total installs
How We Detect Simple Google Calendar Outlook Events Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/simple-google-icalendar-widget/js/simple-ical-block-view.js/wp-content/plugins/simple-google-icalendar-widget/vendor/bs/js/collapse.bundle.js/wp-content/plugins/simple-google-icalendar-widget/vendor/bs/css/collapse.csssimple-google-icalendar-widget/js/simple-ical-block-view.js?ver=simple-google-icalendar-widget/vendor/bs/js/collapse.bundle.js?ver=simple-google-icalendar-widget/vendor/bs/css/collapse.css?ver=HTML / DOM Fingerprints
simple_ical_block_attrswindow.simpleIcalBlock/wp-json/waasdorp-soekhan-wp-plugin-simple-google-icalendar-widget/v1/get_content_by_ids