
XT Event Widget for Social Events Security & Risk Analysis
wordpress.org/plugins/xt-facebook-eventsEasiest way to display Facebook events from your Facebook page to your website using widget or shortcode.
Is XT Event Widget for Social Events Safe to Use in 2026?
Generally Safe
Score 98/100XT Event Widget for Social Events has a strong security track record. Known vulnerabilities have been patched promptly.
The "xt-facebook-events" v1.1.8 plugin exhibits a mixed security posture. While static analysis reveals a generally good practice regarding output escaping and a limited attack surface with no identified unprotected entry points, there are significant concerns related to database interactions and past security issues. The plugin performs SQL queries without prepared statements, which is a common vector for SQL injection vulnerabilities. Although no current vulnerabilities are reported, a past high-severity vulnerability related to Remote File Inclusion is a serious red flag, suggesting a history of critical security flaws that may indicate a lack of robust security development practices or diligent code review. The presence of external HTTP requests also warrants attention as they can be a source of further attack vectors or data leakage if not handled securely.
Key Concerns
- SQL queries not using prepared statements
- History of high severity RFI vulnerability
- External HTTP requests present
XT Event Widget for Social Events Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
XT Event Widget for Social Events <= 1.1.7 - Authenticated (Contributor+) Local File Inclusion
XT Event Widget for Social Events Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
XT Event Widget for Social Events Attack Surface
Shortcodes 1
WordPress Hooks 21
Maintenance & Trust
XT Event Widget for Social Events Maintenance & Trust
Maintenance Signals
Community Trust
XT Event Widget for Social Events Alternatives
Import Social Events
import-facebook-events
Import Facebook events into your WordPress website and/or Event Calendar. Nice Display with shortcode & Event widget.
WP Event Aggregator: Import Eventbrite events, Meetup events, social events and any iCal Events into Event Calendar
wp-event-aggregator
Xylus WP Event Aggregator: Easy way to import Eventbrite events, MeetUp events, Social site Events into your WordPress Event Calendar.
Traking Goals
traking-goals
Description: This plugin allows you to create a goals for Google analytics, and Facebook of predetermined lead type events for telephone links, direc …
Tracking Pixel for Gravity Forms
gf-facebook-pixel-tracking
This plugin provides an easy way to add Facebook event tracking to your Gravity Forms using Facebook’s Tracking Pixel. This flexible plugin works for …
My Agile Pixel – The GDPR Analytics and Tracking Pixel Solution
myagilepixel
Avoid legal issues with Google Analytics, Facebook Pixel, and TikTok Pixel. Boost marketing with custom user properties in Google Analytics 4.
XT Event Widget for Social Events Developer Profile
13 plugins · 110K total installs
How We Detect XT Event Widget for Social Events
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/xt-facebook-events/assets/css/font-awesome.min.css/wp-content/plugins/xt-facebook-events/assets/css/xt-facebook-events.css/wp-content/plugins/xt-facebook-events/assets/css/grid_style2.cssxt-facebook-events/assets/css/font-awesome.min.css?ver=xt-facebook-events/assets/css/xt-facebook-events.css?ver=xt-facebook-events/assets/css/grid_style2.css?ver=HTML / DOM Fingerprints
xt-facebook-events-wrapperdata-fbpageiddata-eventlimitdata-eventdaysdata-showmapdata-showimgdata-showdesc+3 morext_facebook_events_params[xt_facebook_events]