
Events Manager – Event Cancellation Security & Risk Analysis
wordpress.org/plugins/stonehenge-em-cancellationAdds the "Event Cancelled" status to your EM event and auto-emails a notification to your customers.
Is Events Manager – Event Cancellation Safe to Use in 2026?
Generally Safe
Score 85/100Events Manager – Event Cancellation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "stonehenge-em-cancellation" plugin v2.0.2 exhibits a concerning security posture primarily due to its unprotected entry points. The static analysis reveals four AJAX handlers, all of which lack proper authentication checks. This represents a significant attack surface that could be exploited by unauthenticated users. While the plugin doesn't have a history of known vulnerabilities (CVEs) and has no critical taint flows identified, this doesn't negate the immediate risks presented by the unprotected AJAX endpoints. The presence of SQL queries without prepared statements is another area of concern, potentially leading to SQL injection vulnerabilities if data is not handled carefully. The moderate rate of properly escaped output (61%) also suggests potential for cross-site scripting (XSS) vulnerabilities in the remaining 39% of outputs. Despite the lack of historical vulnerabilities, the current state of the code suggests a need for immediate security hardening, particularly around input validation and authentication for its AJAX handlers.
Key Concerns
- AJAX handlers without authentication checks
- SQL queries without prepared statements
- Moderate output escaping rate
Events Manager – Event Cancellation Security Vulnerabilities
Events Manager – Event Cancellation Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Events Manager – Event Cancellation Attack Surface
AJAX Handlers 4
WordPress Hooks 61
Maintenance & Trust
Events Manager – Event Cancellation Maintenance & Trust
Maintenance Signals
Community Trust
Events Manager – Event Cancellation Alternatives
Events Manager – Email Users
events-manager-email-users
Free add-on for Events Manager. Send fully customizable HTML emails to all bookings of a specific event per booking status.
Events Manager – MultiSite Email
events-manager-add-on-multisite-mail-settings
This add-on has been integrated into Events Manager Email Users as of 21-03-2019. Please install that plugin instead.
Event Booking Manager for WooCommerce
mage-eventpress
Flexible WooCommerce plugin for event booking, attendee management, and responsive ticketing with a modern event calendar.
Post Status Notifications
wpsite-post-status-notifications
The Post Status Notifications plugin by 99 Robots provides an easy way to notify Administrators when Contributors submit posts for review or when a Co …
Post Status Notifier Lite
post-status-notifier-lite
Notify on every post change: Flexible rules, custom placeholders and support for all post types and taxonomies.
Events Manager – Event Cancellation Developer Profile
9 plugins · 1K total installs
How We Detect Events Manager – Event Cancellation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.