
Spirit Liturgický kalendár Security & Risk Analysis
wordpress.org/plugins/spirit-liturgicky-kalendarSpirit Liturgický kalendár
Is Spirit Liturgický kalendár Safe to Use in 2026?
Generally Safe
Score 100/100Spirit Liturgický kalendár has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The spirit-liturgicky-kalendar plugin v1.4 exhibits a generally positive security posture, with no recorded vulnerabilities or critical code signals indicating immediate threats. The absence of dangerous functions, raw SQL queries, and file operations suggests a cautious approach to sensitive operations. The use of prepared statements for the single SQL query is a strong security practice. However, the analysis reveals significant areas for improvement. A concerningly low 37% of outputs are properly escaped, potentially exposing the plugin to cross-site scripting (XSS) vulnerabilities. Furthermore, the complete lack of nonce and capability checks on any entry points, including a cron event, presents a substantial risk. This means that these entry points can be triggered by unauthenticated or unauthorized users, opening the door for various attacks. The plugin's history of no vulnerabilities could indicate either genuine good security or simply a lack of thorough historical auditing and potential for undiscovered issues. While the plugin avoids common pitfalls, the identified weaknesses in output escaping and access control require immediate attention to mitigate potential security risks.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
Spirit Liturgický kalendár Security Vulnerabilities
Spirit Liturgický kalendár Code Analysis
SQL Query Safety
Output Escaping
Spirit Liturgický kalendár Attack Surface
WordPress Hooks 11
Scheduled Events 1
Maintenance & Trust
Spirit Liturgický kalendár Maintenance & Trust
Maintenance Signals
Community Trust
Spirit Liturgický kalendár Alternatives
No alternatives data available yet.
Spirit Liturgický kalendár Developer Profile
5 plugins · 530 total installs
How We Detect Spirit Liturgický kalendár
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/spirit-liturgicky-kalendar/css/spirit-lit-kalendar.css/wp-content/plugins/spirit-liturgicky-kalendar/css/spirit-lit-kalendar-admin.css/wp-content/plugins/spirit-liturgicky-kalendar/js/spirit-lit-kalendar-admin.js/wp-content/plugins/spirit-liturgicky-kalendar/js/spirit-lit-kalendar-admin.jsspirit-lit-kalendar/css/spirit-lit-kalendar.css?ver=spirit-lit-kalendar/css/spirit-lit-kalendar-admin.css?ver=spirit-lit-kalendar/js/spirit-lit-kalendar-admin.js?ver=HTML / DOM Fingerprints
tsslk_button_blocktsslk_custom_css_block<!-- Show button to lc.kbs.sk --><!-- Show icon button to lc.kbs.sk --><!-- Custom CSS --><!-- Button settings -->+4 moreid="tsslk_options_ShowButton"name="tsslk_options[ShowButton]"id="tsslk_options_ShowIconInButton"name="tsslk_options[ShowIconInButton]"id="tsslk_options_CustomCSS"name="tsslk_options[CustomCSS]"+12 more