Xllentech Upcoming Events Security & Risk Analysis

wordpress.org/plugins/xllentech-upcoming-events

Xllentech Upcoming Events shows fixed number of Upcoming Islamic Events at any time, out of the php file events data. Sample data file included.

10 active installs v1.2.5 PHP + WP 3.0+ Updated Sep 5, 2024
islamic-eventsupcoming-event-pluginupcoming-islamic-eventsxllentech-islamic-events
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Xllentech Upcoming Events Safe to Use in 2026?

Generally Safe

Score 92/100

Xllentech Upcoming Events has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

Based on the static analysis and vulnerability history, the "xllentech-upcoming-events" plugin version 1.2.5 exhibits a generally good security posture with several positive indicators. Notably, the plugin has a zero attack surface in terms of AJAX handlers, REST API routes, shortcodes, and cron events that are not protected by authentication or permission checks. Furthermore, all identified output is properly escaped, and there are no indications of dangerous functions, file operations, or external HTTP requests. The absence of any known vulnerabilities or CVEs in its history is also a strong positive sign, suggesting diligent security practices during development and maintenance.

However, there are critical areas for concern. The most significant issue is the presence of three SQL queries that are not using prepared statements. This practice is highly risky and makes the plugin susceptible to SQL injection vulnerabilities, especially given the lack of other identified entry points which might have mitigated this risk. The absence of nonce checks and capability checks across all entry points, while not a direct vulnerability in this specific version due to the zero attack surface, represents a potential weakness if new entry points are added in the future without proper security considerations. The taint analysis also showing zero flows is positive, but this is likely a consequence of the limited attack surface and should not be relied upon as a sole indicator of safety without considering the raw SQL issue.

In conclusion, while the "xllentech-upcoming-events" plugin has a clean history and minimal apparent external attack vectors, the use of raw SQL queries without prepared statements introduces a significant, exploitable risk. This oversight overshadows the otherwise positive aspects of the plugin's security. Future development should prioritize addressing this critical SQL injection vulnerability and ensuring that any new functionalities include appropriate authorization and validation mechanisms.

Key Concerns

  • Raw SQL queries without prepared statements
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Xllentech Upcoming Events Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Xllentech Upcoming Events Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared3 total queries

Output Escaping

100% escaped3 total outputs
Attack Surface

Xllentech Upcoming Events Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwidgets_initxllentech-upcoming-events.php:225
actionwp_enqueue_scriptsxllentech-upcoming-events.php:233
Maintenance & Trust

Xllentech Upcoming Events Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedSep 5, 2024
PHP min version
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Alternatives

Xllentech Upcoming Events Alternatives

No alternatives data available yet.

Developer Profile

Xllentech Upcoming Events Developer Profile

Abbas

3 plugins · 140 total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
971 days
View full developer profile
Detection Fingerprints

How We Detect Xllentech Upcoming Events

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/xllentech-upcoming-events/js/xllentech-upcoming-events.js
Script Paths
/wp-content/plugins/xllentech-upcoming-events/js/xllentech-upcoming-events.js
Version Parameters
xllentech-upcoming-events/js/xllentech-upcoming-events.js?ver=

HTML / DOM Fingerprints

CSS Classes
xllentech_upcoming_events_widgetxllentech_upcoming_eventsxllentech-event-descxllentech-event-date
FAQ

Frequently Asked Questions about Xllentech Upcoming Events