
WP FullCalendar Security & Risk Analysis
wordpress.org/plugins/wp-fullcalendarUses the FullCalendar library to create a stunning calendar view of events, posts and other custom post types
Is WP FullCalendar Safe to Use in 2026?
Use With Caution
Score 52/100WP FullCalendar has 2 unpatched vulnerabilities. Evaluate alternatives or apply available mitigations.
The wp-fullcalendar plugin v1.6 presents a moderate security risk due to a combination of static analysis findings and a concerning vulnerability history. While the code shows positive signs such as 100% prepared SQL statements and a high percentage of properly escaped output, the presence of two AJAX handlers without authentication checks is a significant concern. This could allow unauthenticated users to trigger potentially harmful actions.
The plugin's vulnerability history is a more substantial red flag, with a total of four known CVEs, two of which remain unpatched. The common vulnerability types including Exposure of Sensitive Information, Cross-site Scripting, and Missing Authorization suggest recurring security weaknesses that have not been fully addressed. The fact that the most recent vulnerability was dated in 2026, albeit a future date, implies a pattern of unresolved security issues that could be exploited.
Overall, while the codebase exhibits some good security practices, the unpatched vulnerabilities and unprotected entry points create a notable risk. Users should proceed with caution and prioritize updating to versions that address these known security flaws. The plugin's strengths in SQL sanitization and output escaping are overshadowed by the historical and present risks.
Key Concerns
- Unpatched CVEs found
- AJAX handlers without auth checks
- Missing authorization in vulnerability history
- Cross-site Scripting in vulnerability history
- Exposure of Sensitive Information in vulnerability history
WP FullCalendar Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
FullCalendar <= 1.6 - Missing Authorization
FullCalendar <= 1.6 - Unauthenticated Information Exposure
WP FullCalendar <= 1.5 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP FullCalendar <= 1.4.1 - Missing Authorization to Information Disclosure
WP FullCalendar Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP FullCalendar Attack Surface
AJAX Handlers 4
Shortcodes 2
WordPress Hooks 8
Maintenance & Trust
WP FullCalendar Maintenance & Trust
Maintenance Signals
Community Trust
WP FullCalendar Alternatives
ChronoFlo Calendar ShortCode
chronoflo-calendar-shortcode
ChronoFlo Calendar is a beautiful events calendar offering unrivalled visual customization. This plugin provides a shortcode to embed a ChronoFlo cale …
BeatGig WordPress Plugin
beatgig-calendar-embed
BeatGig's event calendar is a modern, beautiful calendar that embeds directly onto your website. When you book new shows on BeatGig, your website …
Timetable and Event Schedule by MotoPress
mp-timetable
Smart event organizer and time-management tool with a clean minimalist design for featuring your timetables and upcoming events.
Event Organiser
event-organiser
Create and maintain events, including complex reoccurring patterns, venue management (with Google Maps or OpenStreetMap), calendars and customisable e …
The Events Calendar Shortcode & Block
the-events-calendar-shortcode
Add shortcode, block, Elementor and Bricks functionality to The Events Calendar Plugin, so you can easily list and promote your events anywhere.
WP FullCalendar Developer Profile
13 plugins · 176K total installs
How We Detect WP FullCalendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-fullcalendar/includes/css/main.css/wp-content/plugins/wp-fullcalendar/includes/js/main.js/wp-content/plugins/wp-fullcalendar/includes/js/fullcalendar.js/wp-content/plugins/wp-fullcalendar/includes/js/popper.js/wp-content/plugins/wp-fullcalendar/includes/js/tippy.js/wp-content/plugins/wp-fullcalendar/includes/js/main.jswp-fullcalendar/includes/css/main.css?ver=wp-fullcalendar/includes/js/main.js?ver=wp-fullcalendar/includes/js/fullcalendar.js?ver=wp-fullcalendar/includes/js/popper.js?ver=wp-fullcalendar/includes/js/tippy.js?ver=HTML / DOM Fingerprints
wp_fullcalendar_params/wp-json/wp-fullcalendar/[fullcalendar][events_fullcalendar]