
Ticket buttons for The Events Calendar Security & Risk Analysis
wordpress.org/plugins/ticket-buttons-for-the-events-calendarAdd a tickets button to your events in The Events Calendar to allow ticket sales on external websites.
Is Ticket buttons for The Events Calendar Safe to Use in 2026?
Generally Safe
Score 100/100Ticket buttons for The Events Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'ticket-buttons-for-the-events-calendar' v1.2.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with exposed attack surfaces is a significant strength. The code also demonstrates good practices by exclusively using prepared statements for all SQL queries and properly escaping a high percentage (83%) of its outputs. The presence of nonce checks further indicates an effort to protect against common web vulnerabilities. The vulnerability history is also very positive, with no known CVEs recorded, suggesting a mature and secure development history.
However, the analysis does reveal a critical lack of capability checks. This means that while nonces might be present, there are no server-side checks to ensure that the logged-in user actually has the necessary permissions to perform the actions associated with these checks. While the total number of entry points is zero, any future additions to the plugin could introduce risks if capability checks are not implemented. The taint analysis, while showing no critical or high severity issues, only analyzed a very small number of flows, leaving room for potential undiscovered vulnerabilities that weren't part of the analyzed paths.
In conclusion, this plugin appears to be well-developed from a security perspective, particularly in its handling of database interactions and output. The lack of historical vulnerabilities is encouraging. The primary concern lies in the complete absence of capability checks, which represents a potential weakness for any future feature additions or in the unlikely event that a previously undiscovered vulnerability allows an attacker to bypass nonce checks. The limited scope of the taint analysis also means that a completely clean bill of health cannot be declared.
Key Concerns
- Missing capability checks
- Limited taint analysis scope
Ticket buttons for The Events Calendar Security Vulnerabilities
Ticket buttons for The Events Calendar Code Analysis
Output Escaping
Data Flow Analysis
Ticket buttons for The Events Calendar Attack Surface
WordPress Hooks 7
Maintenance & Trust
Ticket buttons for The Events Calendar Maintenance & Trust
Maintenance Signals
Community Trust
Ticket buttons for The Events Calendar Alternatives
Events Manager – Calendar, Bookings, Tickets, and more!
events-manager
Events calendar with bookings, scheduling, appointments, event registration, tickets, recurring events, and venue management.
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce
wp-event-manager
Lightweight, scalable and full-featured event listings & management plugin for managing events & tickets from the Frontend and Backend.
Sugar Calendar – Events Calendar, Event Tickets, and Events Management Platform
sugar-calendar-lite
Easily manage events and sell tickets on your WordPress site. Sugar Calendar is easy-to-use, reliable, and exceptionally powerful. See for yourself.
Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered)
wp-event-solution
Create and manage events with a flexible WordPress events calendar plugin. Add recurring events, RSVP, ticket booking, and WooCommerce ticket selling …
Events Calendar by FooEvents
fooevents-calendar
The simplest way to display any post, page or custom post type in a dynamic events calendar on your WordPress website.
Ticket buttons for The Events Calendar Developer Profile
5 plugins · 1K total installs
How We Detect Ticket buttons for The Events Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ticket-buttons-for-the-events-calendar/assets/css/admin.css/wp-content/plugins/ticket-buttons-for-the-events-calendar/assets/js/admin.js/wp-content/plugins/ticket-buttons-for-the-events-calendar/assets/js/admin.js/assets/css/admin.css?ver=/assets/js/admin.js?ver=HTML / DOM Fingerprints
tectb-admin-formtectb-admin-prices-tabletectb-admin-actionstectb-admin-add-pricetbtec-ticketstbtec-ticket-startdate<!-- Tickets button -->data-post-id