
Sogo Calendar Widget Security & Risk Analysis
wordpress.org/plugins/sogo-calendar-widgetA Monthly Calendar widget, highly configurable, enable you to select a post type and field for the date to be used.
Is Sogo Calendar Widget Safe to Use in 2026?
Generally Safe
Score 85/100Sogo Calendar Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sogo-calendar-widget plugin, version 2.1, presents a significant security risk due to its unprotected AJAX handlers. While the plugin boasts clean SQL queries and no recorded vulnerabilities in its history, the lack of authentication checks on two entry points creates a readily exploitable attack surface. This means any unauthenticated user could potentially trigger actions within these AJAX handlers, leading to unintended consequences or system compromise if the underlying functions are insecure. The presence of a dangerous function like `create_function` further exacerbates this risk, as it can be exploited to execute arbitrary PHP code. Additionally, the very low percentage of properly escaped output (6%) indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website through user-controlled input that is displayed without proper sanitization. The lack of vulnerability history might suggest a relatively stable codebase or a lack of previous in-depth security audits, but it does not negate the immediate threats identified in the static analysis.
Key Concerns
- AJAX handlers without auth checks
- Dangerous function create_function found
- Low percentage of properly escaped output
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
Sogo Calendar Widget Security Vulnerabilities
Sogo Calendar Widget Release Timeline
Sogo Calendar Widget Code Analysis
Dangerous Functions Found
Output Escaping
Sogo Calendar Widget Attack Surface
AJAX Handlers 2
WordPress Hooks 1
Maintenance & Trust
Sogo Calendar Widget Maintenance & Trust
Maintenance Signals
Community Trust
Sogo Calendar Widget Alternatives
SOGO Author's Recent Posts
oh-authors-recent-posts-widget
Simple widget to show author's recent post, support RTL
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
Events Widgets For Elementor And The Events Calendar
events-widgets-for-elementor-and-the-events-calendar
The Events Calendar Elementor widgets help you manage and display an upcoming events list with date, time, venue and event ticket booking details.
LTR RTL Admin content
ltrrtl-admin-content
Enable LTR in admin content area. Click the admin bar button to switch between RTL & LTR.
Add to Calendar Button
add-to-calendar-button
Create beautiful buttons, where people can add events to their calendars. Highly customizable. As shortcode or via a convenient block.
Sogo Calendar Widget Developer Profile
4 plugins · 25K total installs
How We Detect Sogo Calendar Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sogo-calendar-widget/css/admin.css/wp-content/plugins/sogo-calendar-widget/js/scripts.js/wp-content/plugins/sogo-calendar-widget/css/cal.css/wp-content/plugins/sogo-calendar-widget/js/scripts.jssogo_calendar_widget/js/scripts.js?ver=1.0sogo_calendar_widget/css/cal.css?ver=1.0HTML / DOM Fingerprints
sogo_calendar_widgetdata-ajaxurldata-headingdata-post_typedata-meta_fielddata-field_formatdata-text_before_detailscal