Spirit Liturgický kalendár Security & Risk Analysis

wordpress.org/plugins/spirit-liturgicky-kalendar

Spirit Liturgický kalendár

10 active installs v1.4 PHP 5.2.4+ WP 3.5+ Updated Mar 5, 2026
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Spirit Liturgický kalendár Safe to Use in 2026?

Generally Safe

Score 100/100

Spirit Liturgický kalendár has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 29d ago
Risk Assessment

The spirit-liturgicky-kalendar plugin v1.4 exhibits a generally positive security posture, with no recorded vulnerabilities or critical code signals indicating immediate threats. The absence of dangerous functions, raw SQL queries, and file operations suggests a cautious approach to sensitive operations. The use of prepared statements for the single SQL query is a strong security practice. However, the analysis reveals significant areas for improvement. A concerningly low 37% of outputs are properly escaped, potentially exposing the plugin to cross-site scripting (XSS) vulnerabilities. Furthermore, the complete lack of nonce and capability checks on any entry points, including a cron event, presents a substantial risk. This means that these entry points can be triggered by unauthenticated or unauthorized users, opening the door for various attacks. The plugin's history of no vulnerabilities could indicate either genuine good security or simply a lack of thorough historical auditing and potential for undiscovered issues. While the plugin avoids common pitfalls, the identified weaknesses in output escaping and access control require immediate attention to mitigate potential security risks.

Key Concerns

  • Low percentage of properly escaped output
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Spirit Liturgický kalendár Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Spirit Liturgický kalendár Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
17
10 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

37% escaped27 total outputs
Attack Surface

Spirit Liturgický kalendár Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actioninitadmin\admin.php:9
actionadmin_initadmin\admin.php:10
actionadmin_enqueue_scriptsadmin\admin.php:11
actionadmin_enqueue_scriptsadmin\admin.php:12
actionadmin_menuadmin\admin.php:17
actiontsslk_fetchLitKalendarDataincludes\lc_kbs_api.php:3
actionwidgets_initincludes\widget.php:4
actioninitlk-block\lk-block.php:12
actionupgrader_process_completespirit-lit-kalendar.php:86
actionwp_enqueue_scriptsspirit-lit-kalendar.php:106
actionwp_enqueue_scriptsspirit-lit-kalendar.php:109

Scheduled Events 1

tsslk_fetchLitKalendarData
Maintenance & Trust

Spirit Liturgický kalendár Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 5, 2026
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

Spirit Liturgický kalendár Alternatives

No alternatives data available yet.

Developer Profile

Spirit Liturgický kalendár Developer Profile

Matej Podstrelenec

5 plugins · 530 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Spirit Liturgický kalendár

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/spirit-liturgicky-kalendar/css/spirit-lit-kalendar.css/wp-content/plugins/spirit-liturgicky-kalendar/css/spirit-lit-kalendar-admin.css/wp-content/plugins/spirit-liturgicky-kalendar/js/spirit-lit-kalendar-admin.js
Script Paths
/wp-content/plugins/spirit-liturgicky-kalendar/js/spirit-lit-kalendar-admin.js
Version Parameters
spirit-lit-kalendar/css/spirit-lit-kalendar.css?ver=spirit-lit-kalendar/css/spirit-lit-kalendar-admin.css?ver=spirit-lit-kalendar/js/spirit-lit-kalendar-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
tsslk_button_blocktsslk_custom_css_block
HTML Comments
<!-- Show button to lc.kbs.sk --><!-- Show icon button to lc.kbs.sk --><!-- Custom CSS --><!-- Button settings -->+4 more
Data Attributes
id="tsslk_options_ShowButton"name="tsslk_options[ShowButton]"id="tsslk_options_ShowIconInButton"name="tsslk_options[ShowIconInButton]"id="tsslk_options_CustomCSS"name="tsslk_options[CustomCSS]"+12 more
FAQ

Frequently Asked Questions about Spirit Liturgický kalendár