
Spirit Events Security & Risk Analysis
wordpress.org/plugins/spirit-eventsSimple event calendar.
Is Spirit Events Safe to Use in 2026?
Generally Safe
Score 85/100Spirit Events has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "spirit-events" v1.0.1 plugin demonstrates a generally positive security posture based on the static analysis. The absence of any identified AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a minimal attack surface. Furthermore, the lack of dangerous functions and file operations is commendable. The code also shows some good practices like the inclusion of a nonce check and a reasonable percentage of properly escaped outputs.
However, there are areas that warrant attention. While only 17% of SQL queries use prepared statements, this is a concern given the presence of six SQL queries. This suggests a potential for SQL injection vulnerabilities, especially if any of these queries handle user-supplied data without proper sanitization, which was not explicitly confirmed or denied by the taint analysis. The complete absence of capability checks is also a notable weakness, meaning that even administrative functions, if they existed, would not be protected by WordPress's role-based access control system.
The plugin's vulnerability history is clean, with zero known CVEs. This is an excellent indicator and suggests that the developers have either been diligent in addressing security or the plugin is relatively new and hasn't yet been the subject of widespread security research. Overall, "spirit-events" v1.0.1 shows promising signs of secure development with a small attack surface and no history of vulnerabilities. The primary concerns revolve around the use of raw SQL and the lack of capability checks, which could present risks if the plugin were to evolve or handle sensitive data in the future.
Key Concerns
- Raw SQL queries present
- Missing capability checks
Spirit Events Security Vulnerabilities
Spirit Events Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Spirit Events Attack Surface
WordPress Hooks 17
Maintenance & Trust
Spirit Events Maintenance & Trust
Maintenance Signals
Community Trust
Spirit Events Alternatives
Timetable and Event Schedule by MotoPress
mp-timetable
Smart event organizer and time-management tool with a clean minimalist design for featuring your timetables and upcoming events.
Event Organiser
event-organiser
Create and maintain events, including complex reoccurring patterns, venue management (with Google Maps or OpenStreetMap), calendars and customisable e …
The Events Calendar Shortcode & Block
the-events-calendar-shortcode
Add shortcode, block, Elementor and Bricks functionality to The Events Calendar Plugin, so you can easily list and promote your events anywhere.
Events Widgets For Elementor And The Events Calendar
events-widgets-for-elementor-and-the-events-calendar
The Events Calendar Elementor widgets help you manage and display an upcoming events list with date, time, venue and event ticket booking details.
Events Shortcodes For The Events Calendar
template-events-calendar
Add The Events Calendar shortcode or Gutenberg block to show upcoming events list with event details on any WordPress page using smart event filters.
Spirit Events Developer Profile
5 plugins · 530 total installs
How We Detect Spirit Events
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/spirit-events/css/spirit-events.css/wp-content/plugins/spirit-events/css/spirit-events-admin.css/wp-content/plugins/spirit-events/css/jquery.timepicker.css/wp-content/plugins/spirit-events/css/bootstrap-datepicker.standalone.css/wp-content/plugins/spirit-events/js/spirit-events-admin.js/wp-content/plugins/spirit-events/js/jquery.timepicker.js/wp-content/plugins/spirit-events/js/bootstrap-datepicker.js/wp-content/plugins/spirit-events/js/datepair.js+1 more/wp-content/plugins/spirit-events/js/spirit-events-admin.js/wp-content/plugins/spirit-events/js/jquery.timepicker.js/wp-content/plugins/spirit-events/js/bootstrap-datepicker.js/wp-content/plugins/spirit-events/js/datepair.js/wp-content/plugins/spirit-events/js/jquery.datepair.jsspirit-events-admin-css?ver=1.0.0spirit-events-admin-js?ver=1.0.0HTML / DOM Fingerprints
tssev_settings_page