
SOWPROG Events Security & Risk Analysis
wordpress.org/plugins/sowprog-eventsDisplays Sowprog events
Is SOWPROG Events Safe to Use in 2026?
Generally Safe
Score 85/100SOWPROG Events has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sowprog-events plugin version 0.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has no known historical vulnerabilities. The attack surface is also relatively small, with a single shortcode as the only identified entry point, and importantly, no unauthenticated entry points were found in the static analysis.
However, several significant concerns are present. The most glaring issue is the extremely low percentage of properly escaped output (15%), indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the static analysis did not identify critical or high severity taint flows, the presence of two flows with unsanitized paths, coupled with poor output escaping, strongly suggests that malicious scripts could be injected and executed. Furthermore, the complete absence of nonce checks and capability checks on its entry points (even though the attack surface is small) is a notable weakness. The plugin also performs file operations and external HTTP requests without clear sanitization or validation mechanisms indicated in the provided data, which could be potential vectors for attack if not handled carefully.
In conclusion, while the plugin benefits from a clean vulnerability history and secure SQL practices, the pervasive lack of output escaping and the absence of essential security checks like nonces and capability checks on its entry points represent substantial security risks. The taint analysis, despite not flagging critical issues, combined with the poor output escaping, warrants significant caution.
Key Concerns
- Low percentage of properly escaped output
- Unsanitized paths in taint flows
- No nonce checks on entry points
- No capability checks on entry points
SOWPROG Events Security Vulnerabilities
SOWPROG Events Release Timeline
SOWPROG Events Code Analysis
Output Escaping
Data Flow Analysis
SOWPROG Events Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
SOWPROG Events Maintenance & Trust
Maintenance Signals
Community Trust
SOWPROG Events Alternatives
SOWPROG import The Events Calendar
sowprog-import-the-events-calendar
Importe dans WordPress, via l'extension The Events Calendar, les événements publiés sur Sowprog (API v1.2).
The Events Calendar
the-events-calendar
The Events Calendar: #1 calendar plugin for WordPress. Create/manage events (virtual too!) on your site with the free plugin.
Events Manager – Calendar, Bookings, Tickets, and more!
events-manager
Events calendar with bookings, scheduling, appointments, event registration, tickets, recurring events, and venue management.
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
Timetable and Event Schedule by MotoPress
mp-timetable
Smart event organizer and time-management tool with a clean minimalist design for featuring your timetables and upcoming events.
SOWPROG Events Developer Profile
2 plugins · 20 total installs
How We Detect SOWPROG Events
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/sowprog-events/includes/js/pickadate.js-3.5.5/lib/picker.js/wp-content/plugins/sowprog-events/includes/js/pickadate.js-3.5.5/lib/picker.date.js/wp-content/plugins/sowprog-events/includes/js/pickadate.js-3.5.5/lib/picker.time.js/wp-content/plugins/sowprog-events/includes/js/pickadate.js-3.5.5/lib/translations/fr_FR.js/wp-content/plugins/sowprog-events/includes/js/pickadate.js-3.5.5/lib/legacy.js/wp-content/plugins/sowprog-events/includes/js/sowprog_events.js/wp-content/plugins/sowprog-events/includes/js/pickadate.js-3.5.5/lib/themes/classic.css/wp-content/plugins/sowprog-events/includes/js/pickadate.js-3.5.5/lib/themes/classic.date.css+3 more/wp-content/plugins/sowprog-events/includes/js/sowprog_events.js/wp-content/plugins/sowprog-events/includes/js/sowprog_events_widget.jsHTML / DOM Fingerprints
icon-searchid="swc_date"name="swc_date"id="swc_query"name="swc_query"id="swc_events_small_div"sowprog_events_widget_parameters/v1/widget/oembed/basic/events//v1/widget/oembed/basic/locations/