
TIVENTS Security & Risk Analysis
wordpress.org/plugins/tivents-products-feedPräsentieren Sie Ihre Produkte von TIVENTS innerhalb Ihrer Website mit einem Shortcode via TIVENTS Public API. Present your TIVENTS products within yo …
Is TIVENTS Safe to Use in 2026?
Generally Safe
Score 100/100TIVENTS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'tivents-products-feed' plugin v2.0.6 demonstrates a generally good security posture with several positive indicators. The complete absence of dangerous functions, file operations, and raw SQL queries, combined with 100% prepared statement usage and a high percentage of properly escaped output, suggests that the developers are adhering to secure coding practices. Furthermore, the lack of any recorded historical vulnerabilities, critical taint flows, or bundled outdated libraries is a significant strength, indicating a stable and well-maintained codebase.
However, there are notable areas of concern. The plugin exposes one REST API route without a permission callback, creating a potential entry point that is not secured by WordPress's role and capability checks. This unprotected endpoint represents a direct risk, as it could be accessed and potentially manipulated by unauthenticated users. The absence of nonce checks and capability checks across other entry points, such as AJAX handlers and shortcodes, also contributes to an increased attack surface. While the static analysis did not uncover specific exploitable flows in this version, the lack of these fundamental security mechanisms could facilitate vulnerabilities in future updates or in conjunction with other plugin/theme issues.
In conclusion, 'tivents-products-feed' v2.0.6 benefits from strong core coding practices regarding database interaction and output sanitization, and its clean vulnerability history is commendable. Nevertheless, the identified unprotected REST API route and the general lack of nonces and capability checks on other entry points are significant weaknesses that require immediate attention. Addressing these specific issues would greatly enhance the plugin's overall security.
Key Concerns
- Unprotected REST API route
- No nonce checks on entry points
- No capability checks on entry points
TIVENTS Security Vulnerabilities
TIVENTS Code Analysis
Output Escaping
TIVENTS Attack Surface
REST API Routes 1
Shortcodes 2
WordPress Hooks 7
Maintenance & Trust
TIVENTS Maintenance & Trust
Maintenance Signals
Community Trust
TIVENTS Alternatives
Events Manager – Calendar, Bookings, Tickets, and more!
events-manager
Events calendar with bookings, scheduling, appointments, event registration, tickets, recurring events, and venue management.
WP Event Manager – Events Calendar, Registrations, Sell Tickets with WooCommerce
wp-event-manager
Lightweight, scalable and full-featured event listings & management plugin for managing events & tickets from the Frontend and Backend.
Sugar Calendar – Events Calendar, Event Tickets, and Events Management Platform
sugar-calendar-lite
Easily manage events and sell tickets on your WordPress site. Sugar Calendar is easy-to-use, reliable, and exceptionally powerful. See for yourself.
Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered)
wp-event-solution
Create and manage events with a flexible WordPress events calendar plugin. Add recurring events, RSVP, ticket booking, and WooCommerce ticket selling …
Events Calendar by FooEvents
fooevents-calendar
The simplest way to display any post, page or custom post type in a dynamic events calendar on your WordPress website.
TIVENTS Developer Profile
1 plugin · 10 total installs
How We Detect TIVENTS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tivents-products-feed/assets/tivents/tiv-plugin.css/wp-content/plugins/tivents-products-feed/assets/fullcalendar/main.min.css/wp-content/plugins/tivents-products-feed/assets/fullcalendar/main.min.js/wp-content/plugins/tivents-products-feed/assets/fullcalendar/locales-all.min.js/wp-content/plugins/tivents-products-feed/assets/tivents/tiv-calendar.css/wp-content/plugins/tivents-products-feed/assets/sweetalert/sweetalert2.min.css/wp-content/plugins/tivents-products-feed/assets/sweetalert/sweetalert2.all.min.js/wp-content/plugins/tivents-products-feed/assets/tivents/tiv-plugin.css/wp-content/plugins/tivents-products-feed/assets/fullcalendar/main.min.css/wp-content/plugins/tivents-products-feed/assets/fullcalendar/main.min.js/wp-content/plugins/tivents-products-feed/assets/fullcalendar/locales-all.min.js/wp-content/plugins/tivents-products-feed/assets/tivents/tiv-calendar.css/wp-content/plugins/tivents-products-feed/assets/sweetalert/sweetalert2.min.css+1 moretivents-products-feed/assets/tivents/tiv-plugin.css?ver=tivents-products-feed/assets/fullcalendar/main.min.css?ver=tivents-products-feed/assets/fullcalendar/main.min.js?ver=tivents-products-feed/assets/fullcalendar/locales-all.min.js?ver=tivents-products-feed/assets/tivents/tiv-calendar.css?ver=tivents-products-feed/assets/sweetalert/sweetalert2.min.css?ver=tivents-products-feed/assets/sweetalert/sweetalert2.all.min.js?ver=HTML / DOM Fingerprints
tivents-products-feed-settingstivents_products_feed-settingsdata-partner-iddata-primary-colordata-secondary-colordata-text-colordata-base-urldata-per-page+1 moreTIVENTPRO_CURRENT_VERSION/wp-json/tivents/v1/calendar[tivents_products[tivents_sponsorships