Event Tickets, RSVPs, Calendar Security & Risk Analysis

wordpress.org/plugins/ticket-spot

Complete ticketing platform: sell tickets, collect RSVPs, branded designs, automated emails, real-time analytics, mobile check-in, seamless integratio …

40 active installs v1.0.3 PHP 7.0+ WP 5.1+ Updated Oct 1, 2025
eventevent-calendarevent-registrationrsvpticket
99
A · Safe
CVEs total1
Unpatched0
Last CVEOct 2, 2025
Safety Verdict

Is Event Tickets, RSVPs, Calendar Safe to Use in 2026?

Generally Safe

Score 99/100

Event Tickets, RSVPs, Calendar has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Oct 2, 2025Updated 7mo ago
Risk Assessment

The ticket-spot plugin version 1.0.3 demonstrates a generally strong security posture based on static analysis, with no identified dangerous functions, all SQL queries using prepared statements, and all output properly escaped. The absence of file operations and external HTTP requests further contributes to a reduced attack surface. Taint analysis also shows no critical or high severity issues, indicating a good effort in sanitizing input. However, the plugin's vulnerability history is a significant concern, with one known CVE recorded. Although it is currently patched, the existence of a past Cross-site Scripting (XSS) vulnerability, even if resolved, highlights a potential area of weakness that malicious actors might try to exploit in future versions or through similar techniques.

While the code itself appears to follow many best practices, the past XSS vulnerability cannot be ignored. The lack of explicit capability checks and nonce checks, while not immediately exploitable due to the limited attack surface (one shortcode), could become a vector if new functionalities are added or if the shortcode's context changes. The plugin's overall security is bolstered by its clean code analysis, but the historical vulnerability suggests a need for continued vigilance and robust testing to prevent recurrence of similar issues. The absence of any unprotected entry points is a positive sign, but the past CVE means the plugin is not entirely without risk.

Key Concerns

  • Past Cross-site Scripting (XSS) vulnerability
  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
1 published

Event Tickets, RSVPs, Calendar Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-9875medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Event Tickets, RSVPs, Calendar <= 1.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 2, 2025 Patched in 1.0.3 (1d)
Version History

Event Tickets, RSVPs, Calendar Release Timeline

v1.0.3Current
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Event Tickets, RSVPs, Calendar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

Event Tickets, RSVPs, Calendar Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ticket_spot] ticket-spot.php:110
WordPress Hooks 5
actionwp_headticket-spot.php:39
actionadmin_enqueue_scriptsticket-spot.php:41
actionadmin_menuticket-spot.php:56
actioninitticket-spot.php:95
filteradmin_footer_textticket-spot.php:97
Maintenance & Trust

Event Tickets, RSVPs, Calendar Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 1, 2025
PHP min version7.0
Downloads2K

Community Trust

Rating80/100
Number of ratings2
Active installs40
Developer Profile

Event Tickets, RSVPs, Calendar Developer Profile

ticketspot

1 plugin · 40 total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Event Tickets, RSVPs, Calendar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ticket-spot/assets/app.js
Script Paths
https://ticketspotapp.com/api/script

HTML / DOM Fingerprints

Data Attributes
id="ticket-spot-settings"
Shortcode Output
<ticket-spot id='
FAQ

Frequently Asked Questions about Event Tickets, RSVPs, Calendar