Upcoming for Calendly Security & Risk Analysis

wordpress.org/plugins/upcoming-for-calendly

Display a list of upcoming already-scheduled Calendly events that still have open slots, and link to their specific registration pages.

100 active installs v2.0.2 PHP 8.0+ WP 5.8+ Updated Jul 10, 2026
calendlycalendly-api
99
A · Safe
CVEs total1
Unpatched0
Last CVEDec 11, 2025
Safety Verdict

Is Upcoming for Calendly Safe to Use in 2026?

Generally Safe

Score 99/100

Upcoming for Calendly has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Dec 11, 2025Updated 1mo ago
Risk Assessment

The "upcoming-for-calendly" plugin v1.2.6 demonstrates generally good security practices, with no critical or high severity issues identified in static analysis or taint flows. The plugin effectively utilizes prepared statements for its SQL queries and has a high rate of output escaping, minimizing common web vulnerabilities. The presence of nonce and capability checks further strengthens its security posture. However, the plugin does exhibit a history of vulnerabilities, specifically one medium-severity Cross-Site Request Forgery (CSRF) issue, even though it is currently patched. This historical pattern suggests a need for ongoing vigilance and thorough review of any future updates. While the current version appears secure based on the provided data, the past vulnerability warrants a slightly cautious approach.

Key Concerns

  • History of medium severity CSRF vulnerability
Vulnerabilities
1 published

Upcoming for Calendly Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-14160medium · 4.3Cross-Site Request Forgery (CSRF)

Upcoming for Calendly <= 1.2.4 - Cross-Site Request Forgery to Settings Update

Dec 11, 2025 Patched in 1.2.5 (1d)
Version History

Upcoming for Calendly Release Timeline

v2.0.2Current
v2.0.1
v2.0
v1.2.7
v1.2.6
v1.2.5
v1.2.41 CVE
v1.2.31 CVE
v1.2.21 CVE
v1.2.11 CVE
Code Analysis
Analyzed Mar 16, 2026

Upcoming for Calendly Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
11 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

92% escaped12 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
uefc_options (includes\settings.php:25)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Upcoming for Calendly Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[upcoming-for-calendly] includes\shortcode.php:20
WordPress Hooks 2
actionadmin_menuincludes\settings.php:20
filterplugin_action_linksincludes\settings.php:92
Maintenance & Trust

Upcoming for Calendly Maintenance & Trust

Maintenance Signals

WordPress version tested7.0.2
Last updatedJul 10, 2026
PHP min version8.0
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs100
Developer Profile

Upcoming for Calendly Developer Profile

justdave

2 plugins · 100 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Upcoming for Calendly

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/upcoming-for-calendly/includes/util.php/wp-content/plugins/upcoming-for-calendly/includes/settings.php/wp-content/plugins/upcoming-for-calendly/includes/shortcode.php

HTML / DOM Fingerprints

CSS Classes
uefc_event_listuefc_event
Data Attributes
event
REST Endpoints
/wp-json/upcoming-for-calendly/v1/settings
Shortcode Output
[upcoming-for-calendly][upcoming-for-calendly event=
FAQ

Frequently Asked Questions about Upcoming for Calendly