
Tockify Events Calendar Security & Risk Analysis
wordpress.org/plugins/tockify-events-calendarTockify Calendar is a modern attractive website calendar. Beautiful. Intuitive. Super-Customizable. Lightning Fast.
Is Tockify Events Calendar Safe to Use in 2026?
Generally Safe
Score 99/100Tockify Events Calendar has a strong security track record. Known vulnerabilities have been patched promptly.
The 'tockify-events-calendar' plugin version 2.3.1 exhibits a mixed security posture. On the positive side, the static analysis reveals no critical code signals such as dangerous functions, raw SQL queries, or file operations. Furthermore, the plugin has no external HTTP requests and no bundled libraries, which generally reduces the attack surface from dependencies. However, several significant concerns are present. The output escaping is notably poor, with only 33% of outputs properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The complete absence of nonce checks and capability checks, particularly given the presence of a shortcode, is alarming as it means user actions initiated via the shortcode might not be properly authorized or validated. The vulnerability history, while showing no currently unpatched vulnerabilities, reveals a past medium-severity CVE related to XSS, confirming the susceptibility to this type of attack. The fact that a medium severity XSS vulnerability was present in the past and the current code has such poor output escaping suggests a persistent weakness in handling user-provided data safely.
Key Concerns
- Poor output escaping (33% properly escaped)
- No nonce checks on entry points
- No capability checks on entry points
- Medium severity CVE in history
Tockify Events Calendar Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Tockify Events Calendar <= 2.2.13 - Authenticated (Contributor+) Stored Cross-Site Scripting
Tockify Events Calendar Code Analysis
Output Escaping
Tockify Events Calendar Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Tockify Events Calendar Maintenance & Trust
Maintenance Signals
Community Trust
Tockify Events Calendar Alternatives
Localendar Calendar for WordPress
localendar-for-wordpress
Thanks for checking out the localendar calendar plugin for WordPress. We have been powering web calendars for thousands of sites for over 16 years, an …
Timetable and Event Schedule by MotoPress
mp-timetable
Smart event organizer and time-management tool with a clean minimalist design for featuring your timetables and upcoming events.
Event Organiser
event-organiser
Create and maintain events, including complex reoccurring patterns, venue management (with Google Maps or OpenStreetMap), calendars and customisable e …
The Events Calendar Shortcode & Block
the-events-calendar-shortcode
Add shortcode, block, Elementor and Bricks functionality to The Events Calendar Plugin, so you can easily list and promote your events anywhere.
Events Widgets For Elementor And The Events Calendar
events-widgets-for-elementor-and-the-events-calendar
The Events Calendar Elementor widgets help you manage and display an upcoming events list with date, time, venue and event ticket booking details.
Tockify Events Calendar Developer Profile
1 plugin · 2K total installs
How We Detect Tockify Events Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tockify-events-calendar/tockify.phphttps://public.tockify.com/browser/embed.jsHTML / DOM Fingerprints
data-tockify-history.pushState_tkf.loadDeclaredCalendars<div data-tockify-<script type='text/javascript'>if (window._tkf && window._tkf.loadDeclaredCalendars) {window._tkf.loadDeclaredCalendars();}</script>