Super Simple Events List Security & Risk Analysis

wordpress.org/plugins/super-simple-events-list

Create and customise a simple events (and past events) list. Display them on your page with a shortcode. In the WP admin it has the look and feel of W …

0 active installs v0.9 PHP + WP 5.4+ Updated Sep 12, 2020
events-calendar-cpt
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Super Simple Events List Safe to Use in 2026?

Generally Safe

Score 85/100

Super Simple Events List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "super-simple-events-list" v0.9 plugin demonstrates a generally strong security posture based on the provided static analysis. The absence of dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests are all positive indicators. The plugin also incorporates a nonce check and a capability check, suggesting an awareness of common security vulnerabilities. The high percentage of properly escaped output further reinforces this good practice.

The primary areas of concern lie in the limited attack surface analysis, which shows no unprotected entry points, but also no taint analysis. While the static analysis did not uncover any critical vulnerabilities, the lack of taint analysis means that potential data flow vulnerabilities, where user input could be processed in an unsafe manner, might have been missed. The vulnerability history is clean, with no known CVEs, which is a significant strength and suggests the plugin has historically been well-maintained from a security perspective.

In conclusion, the plugin appears to be built with security in mind, with good coding practices observed. The absence of historical vulnerabilities is a strong positive. However, the lack of taint analysis is a notable gap, as it limits the confidence that all potential vulnerabilities have been identified. The limited number of entry points and their protection are positive, but the absence of taint analysis prevents a complete assessment of the security of these entry points against more sophisticated attacks.

Key Concerns

  • Lack of taint analysis
  • Limited attack surface details (no unprotected entry points)
  • 91% output escaping (3% unescaped)
Vulnerabilities
None known

Super Simple Events List Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Super Simple Events List Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Super Simple Events List Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
31 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped34 total outputs
Attack Surface

Super Simple Events List Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[bcssel_upcoming_events] includes\shortcode.php:116
[bcssel_past_events] includes\shortcode.php:231
WordPress Hooks 10
filterthe_contentincludes\content.php:5
actionadmin_menuincludes\docs.php:3
actionwp_enqueue_scriptsincludes\init.php:9
actionadmin_enqueue_scriptsincludes\init.php:15
actioninitincludes\init.php:67
actionadd_meta_boxesincludes\wpadmin.php:12
actionsave_postincludes\wpadmin.php:50
filterparse_queryincludes\wpadmin.php:100
actionload-edit.phpincludes\wpadmin.php:118
filtermanage_posts_columnsincludes\wpadmin.php:199
Maintenance & Trust

Super Simple Events List Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedSep 12, 2020
PHP min version
Downloads854

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

Super Simple Events List Alternatives

No alternatives data available yet.

Developer Profile

Super Simple Events List Developer Profile

Rik

5 plugins · 6K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Super Simple Events List

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/super-simple-events-list/assets/bcssel.css/wp-content/plugins/super-simple-events-list/assets/bcssel-admin.css

HTML / DOM Fingerprints

CSS Classes
bcsselbcssel_upcoming_eventsbcssel_listbcssel_list_itembcssel_list_linkbcssel_col_imgbcssel_imgbcssel_no_img+11 more
Data Attributes
data-bcssel-datedata-bcssel-timedata-bcssel-loc
Shortcode Output
<div id="bcssel" class="bcssel bcssel_upcoming_events bcssel_list"><div class="bcssel_list_item"><a href="" class="bcssel_list_link">
FAQ

Frequently Asked Questions about Super Simple Events List