
Verowa Connect Security & Risk Analysis
wordpress.org/plugins/verowa-connectInclude your Verowa events and much more seamlessly into your WordPress project. Customize the HTML output with flexible templates and various shortco …
Is Verowa Connect Safe to Use in 2026?
Generally Safe
Score 95/100Verowa Connect has a strong security track record. Known vulnerabilities have been patched promptly.
The "verowa-connect" plugin v3.3.4 exhibits a mixed security posture. While it demonstrates good practices in many areas, such as a high percentage of prepared SQL statements and properly escaped output, significant concerns are present. The static analysis reveals a substantial attack surface, with 9 out of 38 entry points lacking authentication or permission checks, particularly within its REST API routes. The taint analysis is also concerning, with 13 high-severity flows identified, indicating potential pathways for malicious data to be processed without adequate sanitization, even though no critical severity flows were found. The vulnerability history, with a total of 4 known CVEs including one high and three medium severity vulnerabilities, points to a pattern of past security weaknesses, even though none are currently unpatched. The types of past vulnerabilities (XSS and SQL Injection) align with the potential risks highlighted by the taint analysis. Overall, while the plugin has strengths in code hygiene, the unprotected entry points and high-severity taint flows, coupled with a history of exploitable vulnerabilities, present a notable risk that requires careful consideration and mitigation.
Key Concerns
- High severity taint flows found
- Unprotected REST API routes
- Unprotected AJAX handlers
- One high severity past CVE
- Three medium severity past CVEs
Verowa Connect Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Verowa Connect <= 3.2.3 - Authenticated (Contributor+) Stored Cross-Site Scripting
Verowa Connect <= 3.0.4 - Reflected Cross-Site Scripting
Verowa Connect <= 3.0.5 - Authenticated (Administrator+) SQL Injection
Verowa Connect <= 3.0.1 - Unauthenticated SQL Injection
Verowa Connect Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Verowa Connect Attack Surface
REST API Routes 13
Shortcodes 25
WordPress Hooks 71
Scheduled Events 2
Maintenance & Trust
Verowa Connect Maintenance & Trust
Maintenance Signals
Community Trust
Verowa Connect Alternatives
Swiss 5-cent Rounding
swiss-5-cent-rounding
Swiss 5-cent Rounding allows you to easily apply rounding to the nearest 0.05 interval for discount and VAT amounts in your WooCommerce shop.
Swiss QR Bill
swiss-qr-bill
Swiss QR Bill extends WooCommerce with a new payment method, allowing you to easily send automated and standardized Swiss QR bills to your clients.
Church Social
church-social
This plugin allows churches to display content from their Church Social account on their WordPress website.
Church Options
church-options
An all-in-one solution for churches to add the custom post types and custom fields they need for an effective website. Compatible theme required.
Integration for ChurchSuite
cs-integration
Integration for ChurchSuite is a plugin to enable display of data from ChurchSuite JSON feeds
Verowa Connect Developer Profile
2 plugins · 100 total installs
How We Detect Verowa Connect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/verowa-connect/css/jquery-ui.min.css/wp-content/plugins/verowa-connect/js/functions.min.js/wp-content/plugins/verowa-connect/css/shared-vc-styles.min.css/wp-content/plugins/verowa-connect/css/verowa-connect.min.css/wp-content/plugins/verowa-connect/css/verowa-agenda.min.css/wp-content/plugins/verowa-connect/js/verowa-agenda.min.js/wp-content/plugins/verowa-connect/css/shared-vc-styles.css/wp-content/plugins/verowa-connect/js/functions.min.js/wp-content/plugins/verowa-connect/js/verowa-agenda.min.jsverowa-connect/css/jquery-ui.min.css?ver=verowa-connect/js/functions.min.js?ver=verowa-connect/css/shared-vc-styles.min.css?ver=verowa-connect/css/verowa-connect.min.css?ver=verowa-connect/css/verowa-agenda.min.css?ver=verowa-connect/js/verowa-agenda.min.js?ver=HTML / DOM Fingerprints
verowa-connect-sharedverowa-agendadata-verowa-templatedata-verowa-rolesverowa_L10n_functionsverowa_L10n_agenda/wp-json/verowa-connect/v1/events[verowa-agenda[verowa-event-list[verowa-event-details-json[verowa-image