Display Eventbrite Events Security & Risk Analysis

wordpress.org/plugins/widget-for-eventbrite-api

Display your upcoming Eventbrite events quickly and easily.

3K active installs v6.5.9 PHP 7.4+ WP 5.6+ Updated Feb 26, 2026
eventbriteeventbrite-shortcodeeventbrite-widgeteventswidget
98
A · Safe
CVEs total1
Unpatched0
Last CVEMay 7, 2025
Safety Verdict

Is Display Eventbrite Events Safe to Use in 2026?

Generally Safe

Score 98/100

Display Eventbrite Events has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 7, 2025Updated 1mo ago
Risk Assessment

The "widget-for-eventbrite-api" plugin v6.5.9 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and has a high percentage of properly escaped output. The absence of file operations and the low count of external HTTP requests are also encouraging. However, a significant concern lies in its attack surface, with 8 out of 11 entry points lacking authentication checks. This presents a considerable risk of unauthorized access or manipulation through its AJAX handlers. Furthermore, the plugin has a history of a high-severity vulnerability, specifically Remote File Inclusion, indicating a potential for serious security breaches if not diligently patched. Although the current version has no unpatched CVEs, the past vulnerability type and the significant number of unprotected AJAX handlers warrant caution. The presence of a bundled library (Freemius v1.0) also introduces a potential dependency risk if it's outdated or contains its own vulnerabilities, although no specific version issues are detailed here.

Key Concerns

  • Multiple AJAX handlers without authentication checks
  • History of high severity RFI vulnerability
  • Bundled Freemius library (potential outdated dependency)
Vulnerabilities
1

Display Eventbrite Events Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2025-47510high · 8.8Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')

Display Eventbrite Events <= 6.2.6 - Authenticated (Contributor+) Local File Inclusion

May 7, 2025 Patched in 6.3 (7d)
Code Analysis
Analyzed Mar 16, 2026

Display Eventbrite Events Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
9 prepared
Unescaped Output
19
305 escaped
Nonce Checks
9
Capability Checks
15
File Operations
0
External Requests
1
Bundled Libraries
1

Bundled Libraries

Freemius1.0

SQL Query Safety

100% prepared9 total queries

Output Escaping

94% escaped324 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
update_elementor_widget_content (includes\widgets\elementor\class-eventbrite-widget-elementor-helpers.php:596)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
8 unprotected

Display Eventbrite Events Attack Surface

Entry Points11
Unprotected8

AJAX Handlers 9

authwp_ajax_update_api_optionadmin\class-admin-setup-wizard.php:28
authwp_ajax_wfea_dismiss_noticeincludes\class-core.php:170
authwp_ajax_update_widget_contentincludes\class-core.php:172
authwp_ajax_fetch_organizations_for_keyincludes\class-core.php:173
authwp_ajax_fetch_events_for_keyincludes\class-core.php:174
authwp_ajax_fetch_organizers_for_keyincludes\class-core.php:175
authwp_ajax_fetch_venues_optionsincludes\class-core.php:176
authwp_ajax_fetch_api_key_optionsincludes\class-core.php:177
authwp_ajax_validate_dateincludes\class-core.php:178

Shortcodes 2

[wfea] includes\class-core.php:278
[wfea] shortcodes\class-shortcodes.php:49
WordPress Hooks 43
actionadmin_enqueue_scriptsadmin\class-admin-pages.php:215
filterscreen_layout_columnsadmin\class-admin-pages.php:217
actionadmin_enqueue_scriptsadmin\class-admin-setup-wizard.php:247
filterscreen_layout_columnsadmin\class-admin-setup-wizard.php:250
filterblock_type_metadatablocks\class-blocks.php:59
filterrest_endpointsblocks\class-blocks.php:60
filterregister_block_type_argsblocks\class-blocks.php:63
actionadmin_menuincludes\class-core.php:135
actionadmin_menuincludes\class-core.php:139
actionadmin_enqueue_scriptsincludes\class-core.php:164
actionadmin_enqueue_scriptsincludes\class-core.php:165
actionenqueue_block_editor_assetsincludes\class-core.php:166
actionenqueue_block_editor_assetsincludes\class-core.php:167
actionadmin_noticesincludes\class-core.php:168
actionadmin_initincludes\class-core.php:169
filtersite_status_testsincludes\class-core.php:171
actioninitincludes\class-core.php:179
actionelementor/widgets/registerincludes\class-core.php:182
filterwp_kses_allowed_htmlincludes\class-core.php:191
actioninitincludes\class-core.php:213
filterjetpack_photon_skip_for_urlincludes\class-core.php:214
filterwfea_the_contentincludes\class-core.php:220
actionwp_enqueue_scriptsincludes\class-core.php:226
actionwp_enqueue_scriptsincludes\class-core.php:227
filterscript_loader_tagincludes\class-core.php:229
actionwp_headincludes\class-core.php:235
actionwidgets_initincludes\class-core.php:239
actioninitincludes\class-core.php:240
actioninitincludes\class-core.php:241
actionenqueue_block_assetsincludes\class-core.php:262
filteraioseo_conflicting_shortcodesincludes\class-core.php:274
filterhttp_request_timeoutincludes\class-eventbrite-manager.php:335
filterconnect_urlincludes\class-freemius-config.php:45
filterplugin_iconincludes\class-freemius-config.php:55
filteris_submenu_visibleincludes\class-freemius-config.php:59
filtershow_deactivation_feedback_formincludes\class-freemius-config.php:74
filterwidget-for-eventbrite-api_template_pathsincludes\class-template-loader.php:53
filterwidget-for-eventbrite-api_get_template_partincludes\class-template-loader.php:74
filterwidget-for-eventbrite-api_template_pathsincludes\class-utilities.php:845
actionelementor/widgets/registerincludes\class-widgets.php:74
filterwfea_combined_date_time_date_formattemplates__free\layout_card.php:10
actionsetup_themewidget-for-eventbrite-api.php:68
actionafter_uninstallwidget-for-eventbrite-api.php:76
Maintenance & Trust

Display Eventbrite Events Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 26, 2026
PHP min version7.4
Downloads272K

Community Trust

Rating98/100
Number of ratings27
Active installs3K
Developer Profile

Display Eventbrite Events Developer Profile

fullworks

13 plugins · 79K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
1372 days
View full developer profile
Detection Fingerprints

How We Detect Display Eventbrite Events

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/widget-for-eventbrite-api/admin/js/script.js/wp-content/plugins/widget-for-eventbrite-api/admin/css/style.css/wp-content/plugins/widget-for-eventbrite-api/includes/js/vendors/moment.min.js/wp-content/plugins/widget-for-eventbrite-api/includes/js/vendors/datetimepicker.js/wp-content/plugins/widget-for-eventbrite-api/includes/js/vendors/moment.min.js/wp-content/plugins/widget-for-eventbrite-api/includes/js/vendors/datetimepicker.js
Script Paths
/wp-content/plugins/widget-for-eventbrite-api/admin/js/script.js/wp-content/plugins/widget-for-eventbrite-api/includes/js/vendors/moment.min.js/wp-content/plugins/widget-for-eventbrite-api/includes/js/vendors/datetimepicker.js
Version Parameters
/wp-content/plugins/widget-for-eventbrite-api/admin/js/script.js?ver=/wp-content/plugins/widget-for-eventbrite-api/admin/css/style.css?ver=/wp-content/plugins/widget-for-eventbrite-api/includes/js/vendors/moment.min.js?ver=/wp-content/plugins/widget-for-eventbrite-api/includes/js/vendors/datetimepicker.js?ver=

HTML / DOM Fingerprints

CSS Classes
wfea-settings
Data Attributes
id="fx-smb-form"
JS Globals
postboxes
FAQ

Frequently Asked Questions about Display Eventbrite Events