
The Events Calendar PRO Alarm Security & Risk Analysis
wordpress.org/plugins/the-events-calendar-pro-alarmAdd alarm/alert to iCal feed created from The Events Calendar PRO plugin.
Is The Events Calendar PRO Alarm Safe to Use in 2026?
Generally Safe
Score 100/100The Events Calendar PRO Alarm has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of "the-events-calendar-pro-alarm" v3.1.0 reveals a remarkably clean code base with no identified vulnerabilities or dangerous functions. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, all observed SQL queries utilize prepared statements, and there are no unescaped outputs or file operations, indicating good coding practices in these critical areas. The plugin also refrains from making external HTTP requests, which can sometimes introduce vulnerabilities.
While the lack of any recorded CVEs in its vulnerability history is a positive sign, it's important to note that this can also indicate a lack of past extensive security auditing or that the plugin is relatively new or has not been targeted. The complete absence of taint flows and unsanitized paths further strengthens the perception of a secure plugin. However, the zero capability checks and zero nonce checks are notable omissions. While the limited attack surface might mitigate the immediate risk, these are fundamental security mechanisms that should ideally be present, especially if the plugin were to evolve and introduce more interaction points.
In conclusion, "the-events-calendar-pro-alarm" v3.1.0 presents a strong security posture based on the provided static analysis. The code is clean, and there are no immediate exploitable vulnerabilities detected. The primary area for improvement lies in the implementation of capability and nonce checks, which would further harden the plugin against potential future threats, even with its current minimal attack surface.
Key Concerns
- Missing capability checks
- Missing nonce checks
The Events Calendar PRO Alarm Security Vulnerabilities
The Events Calendar PRO Alarm Code Analysis
The Events Calendar PRO Alarm Attack Surface
WordPress Hooks 4
Maintenance & Trust
The Events Calendar PRO Alarm Maintenance & Trust
Maintenance Signals
Community Trust
The Events Calendar PRO Alarm Alternatives
The Events Calendar Outlook Import Fix
the-events-calendar-outlook-import-fix
Fix import of calendar events from The Events Calendar to Outlook.
Duplicate TEC Event
duplicate-tec-event
Adds the ability to duplicate an event created by Modern Tribe's The Event Calendar plugin.
Display Event Location for The Events Calendar
display-event-locations-tec
This plugin works with The Events Calendar by Modern Tribe. It adds an event's location information to the tooltip on the monthly calendar view.
The Events Calendar User CSS
the-events-calendar-user-css
A plugin to correctly load users custom CSS overrides for The Events Calendar PRO.
Block used images
block-used-images
Modern Tribe Events is a great plugin.
The Events Calendar PRO Alarm Developer Profile
12 plugins · 43K total installs
How We Detect The Events Calendar PRO Alarm
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/the-events-calendar-pro-alarm/dist/css/the-events-calendar-pro-alarm.css/wp-content/plugins/the-events-calendar-pro-alarm/dist/js/the-events-calendar-pro-alarm.js/wp-content/plugins/the-events-calendar-pro-alarm/dist/js/the-events-calendar-pro-alarm.jsthe-events-calendar-pro-alarm/dist/css/the-events-calendar-pro-alarm.css?ver=the-events-calendar-pro-alarm/dist/js/the-events-calendar-pro-alarm.js?ver=