Easy to use Events Uploader for Ultimate Member. Give your users the option to create events

10 active installs v1.0.0 PHP 5.6+ WP 3.0.1+ Updated Oct 25, 2018
eventsultimate-memberultimate-member-eventsultimatememberultimatemember-events-calendar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is UM Events Safe to Use in 2026?

Generally Safe

Score 85/100

UM Events has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "um-events-lite-for-ultimate-member" plugin v1.0.0 exhibits a mixed security posture. While it shows strengths in avoiding dangerous functions, file operations, and external HTTP requests, and uses prepared statements for a majority of its SQL queries, significant concerns arise from its attack surface. A substantial portion of its AJAX handlers lack authentication checks, creating potential entry points for unauthorized actions. The taint analysis also indicates a flow with unsanitized paths, which could lead to vulnerabilities if not addressed, though it's not classified as critical or high severity in this analysis.

The plugin's vulnerability history is clean, with no known CVEs recorded. This absence of past vulnerabilities is a positive sign and suggests a potentially robust development approach. However, it's crucial to remember that a lack of past issues doesn't guarantee future security, especially given the identified attack surface concerns and the presence of unsanitized paths in the taint analysis. The plugin's strengths lie in its foundational security practices, but the unprotected AJAX endpoints and the taint flow represent areas requiring immediate attention to mitigate potential risks.

Key Concerns

  • Unprotected AJAX handlers
  • Taint flow with unsanitized paths
  • Limited nonce checks on AJAX
  • Missing capability checks
  • Output not always properly escaped
Vulnerabilities
None known

UM Events Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

UM Events Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
2 prepared
Unescaped Output
33
51 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

jQuery

SQL Query Safety

67% prepared3 total queries

Output Escaping

61% escaped84 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
um_event_get_form (includes\class-um-events-ajax.php:53)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

UM Events Attack Surface

Entry Points5
Unprotected4

AJAX Handlers 5

authwp_ajax_um_events_saveincludes\class-um-events-ajax.php:8
authwp_ajax_um_event_get_formincludes\class-um-events-ajax.php:9
authwp_ajax_um_event_get_viewincludes\class-um-events-ajax.php:10
noprivwp_ajax_um_event_get_viewincludes\class-um-events-ajax.php:11
authwp_ajax_um_event_deleteincludes\class-um-events-ajax.php:12
WordPress Hooks 17
actionadmin_menuincludes\class-um-events-admin.php:82
actionadmin_initincludes\class-um-events-admin.php:83
actionadmin_enqueue_scriptsincludes\class-um-events-admin.php:84
actioncmb2_admin_initincludes\class-um-events-admin.php:85
actionum_after_event_savedincludes\um-events-functions.php:151
actioninitincludes\um-events-functions.php:248
actioninitincludes\um-events-posttypes.php:2
actionadd_meta_boxesincludes\um-events-posttypes.php:57
actionsave_postincludes\um-events-posttypes.php:117
actionwp_footerincludes\um-events-template.php:4
actionum_events_tab_headerincludes\um-events-template.php:5
actionum_event_loop_view_contentincludes\um-events-template.php:6
actionplugins_loadedum-events-lite-for-ultimate-member.php:36
filterum_user_profile_tabsum-events-lite-for-ultimate-member.php:96
filterum_profile_tabsum-events-lite-for-ultimate-member.php:98
actionum_profile_content_eventsum-events-lite-for-ultimate-member.php:101
actionwp_enqueue_scriptsum-events-lite-for-ultimate-member.php:102
Maintenance & Trust

UM Events Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedOct 25, 2018
PHP min version5.6
Downloads2K

Community Trust

Rating20/100
Number of ratings1
Active installs10
Developer Profile

UM Events Developer Profile

SuitePlugins

17 plugins · 2K total installs

90
trust score
Avg Security Score
86/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect UM Events

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/um-events-lite-for-ultimate-member/assets/css/um-events.css/wp-content/plugins/um-events-lite-for-ultimate-member/assets/css/um-events.min.css/wp-content/plugins/um-events-lite-for-ultimate-member/assets/js/um-events.js/wp-content/plugins/um-events-lite-for-ultimate-member/assets/js/um-events.min.js
Script Paths
//code.jquery.com/ui/1.12.1/themes/flick/jquery-ui.css/wp-content/plugins/um-events-lite-for-ultimate-member/assets/css/um-events.min.css/wp-content/plugins/um-events-lite-for-ultimate-member/assets/css/um-events.css/wp-content/plugins/um-events-lite-for-ultimate-member/assets/js/um-events.min.js/wp-content/plugins/um-events-lite-for-ultimate-member/assets/js/um-events.js
Version Parameters
um-events-lite-for-ultimate-member/assets/css/um-events.css?ver=um-events-lite-for-ultimate-member/assets/js/um-events.js?ver=

HTML / DOM Fingerprints

CSS Classes
um-faicon-calendar
JS Globals
um_event_config
FAQ

Frequently Asked Questions about UM Events