
WP Month Calendar Security & Risk Analysis
wordpress.org/plugins/wp-month-calendarA modified version of the Widget build in to WordPress. It displays a link for each month, not for each day.
Is WP Month Calendar Safe to Use in 2026?
Generally Safe
Score 85/100WP Month Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-month-calendar" v1.0 plugin exhibits a generally good security posture due to its seemingly limited attack surface and lack of reported vulnerabilities. The static analysis shows no identified AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential entry points for attackers. Furthermore, the absence of dangerous functions and file operations is positive. However, several areas raise concerns. Notably, 100% of the detected SQL queries are not using prepared statements, which is a significant risk for SQL injection vulnerabilities. Additionally, while there are many output operations, a substantial portion (41%) are not properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities.
The plugin's vulnerability history is clean, with no known CVEs. This, combined with the lack of identified taint flows, suggests that if the plugin was developed with security in mind, it has been successful so far. However, the absence of nonce checks and capability checks across all entry points (of which there are none explicitly identified, but this statement implies a potential oversight should any be introduced) is a weakness. In conclusion, while the plugin appears robust from its limited history and attack surface, the critical findings regarding unsanitized SQL queries and unescaped output represent tangible and potentially severe security risks that require immediate attention. The lack of any historical vulnerabilities might be due to its limited scope or adoption, and should not be a sole reason to dismiss the static analysis findings.
Key Concerns
- All SQL queries lack prepared statements
- Significant portion of outputs not properly escaped
- 0% capability checks found
- 0% nonce checks found
WP Month Calendar Security Vulnerabilities
WP Month Calendar Code Analysis
SQL Query Safety
Output Escaping
WP Month Calendar Attack Surface
WordPress Hooks 5
Maintenance & Trust
WP Month Calendar Maintenance & Trust
Maintenance Signals
Community Trust
WP Month Calendar Alternatives
Simple Calendar – Google Calendar Plugin
google-calendar-events
Add Google Calendar events to your WordPress site in minutes. Beautiful calendar displays. Mobile responsive.
Events Widgets For Elementor And The Events Calendar
events-widgets-for-elementor-and-the-events-calendar
The Events Calendar Elementor widgets help you manage and display an upcoming events list with date, time, venue and event ticket booking details.
Add to Calendar Button
add-to-calendar-button
Create beautiful buttons, where people can add events to their calendars. Highly customizable. As shortcode or via a convenient block.
Compact Archives
compact-archives
Displays a smart monthly archive of posts in a more compact form rather than the default long archive widget.
Upcoming Events Lists
upcoming-events-lists
A WordPress plugin to show a list of upcoming events on the front-end.
WP Month Calendar Developer Profile
2 plugins · 20 total installs
How We Detect WP Month Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-month-calendar/css/month-calendar.css/wp-content/plugins/wp-month-calendar/js/month-calendar.js/wp-content/plugins/wp-month-calendar/js/month-calendar.jswp-month-calendar/css/month-calendar.css?ver=wp-month-calendar/js/month-calendar.js?ver=HTML / DOM Fingerprints
widget_wp_month_calendarcalendar_wrapid="wp-calendar"id="prev"id="next"id="today"<table id="wp-calendar"<td id="prev"<td id="next"<td id="today"