
VS Event List Security & Risk Analysis
wordpress.org/plugins/very-simple-event-listWith this lightweight plugin you can create an event list.
Is VS Event List Safe to Use in 2026?
Generally Safe
Score 100/100VS Event List has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "very-simple-event-list" v19.9 presents a generally strong security posture with a notable lack of critical vulnerabilities reported historically and in static analysis. The plugin demonstrates good practices by properly escaping nearly all output and avoids dangerous functions, file operations, and external HTTP requests, which are common sources of vulnerabilities. The absence of known CVEs and a clean taint analysis report further contribute to this positive assessment. However, there are specific areas that warrant attention and could introduce risk.
The primary concern lies in the handling of SQL queries. All six SQL queries are executed without the use of prepared statements. While there are no direct indicators of immediate SQL injection in the static analysis, this is a significant deviation from secure coding practices and leaves the plugin susceptible to such attacks, especially if user-supplied data is ever directly incorporated into these queries. Furthermore, while the plugin has a total of six entry points, all of them are shortcodes, and the analysis indicates that none of these are directly unprotected, which is positive. However, the limited scope of nonce and capability checks (only one of each) on potentially complex shortcode operations could be a weakness if those shortcodes handle sensitive data or operations.
The vulnerability history shows a perfect record with zero known CVEs across all severity levels, which is an excellent indicator of the developer's diligence in maintaining security. This, combined with the clean taint analysis, suggests a low likelihood of critical or high-severity vulnerabilities being present or overlooked. Despite the strength in other areas, the unqualified use of raw SQL queries is a considerable weakness that prevents a fully confident security assessment and warrants a deduction.
Key Concerns
- All SQL queries lack prepared statements
- Limited nonce/capability checks for shortcodes
VS Event List Security Vulnerabilities
VS Event List Code Analysis
SQL Query Safety
Output Escaping
VS Event List Attack Surface
Shortcodes 6
WordPress Hooks 26
Maintenance & Trust
VS Event List Maintenance & Trust
Maintenance Signals
Community Trust
VS Event List Alternatives
Eventin – Events Calendar, Event Booking, Ticket & Registration (AI Powered)
wp-event-solution
Create and manage events with a flexible WordPress events calendar plugin. Add recurring events, RSVP, ticket booking, and WooCommerce ticket selling …
Quick Event Manager
quick-event-manager
Simple event manager. No messing about, just add events and a shortcode and the plugin does the rest for you.
Events as Posts
events-as-posts
A simple plugin that allows you to post events on your site.
Sched Event Management Software
embed-sched
Easily manage and promote events! Complete with mobile apps, multiple event calendar views, customization, speaker/sponsor directories and more!
FT Calendar
ft-calendar
A calendar plugin supporting multiple calendars, recurring events, and several different widgets / shortcodes. More info at http://calendar-plugin.com
VS Event List Developer Profile
19 plugins · 23K total installs
How We Detect VS Event List
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/very-simple-event-list/css/vsel-style.min.cssHTML / DOM Fingerprints
vsel-event-list-container<!-- Very Simple Event List Widget -->data-event-iddata-start-datedata-end-datedata-locationdata-mapdata-link+5 morevsel_params/wp-json/vsel/v1/events[vsel_event_list][vsel_upcoming_event]