
YY EVENTS Security & Risk Analysis
wordpress.org/plugins/yy-eventsEnables you to show a list of Events, Concerts, Sports and Theater Listings.
Is YY EVENTS Safe to Use in 2026?
Generally Safe
Score 85/100YY EVENTS has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "yy-events" v1.4 plugin presents a mixed security posture. On the positive side, it demonstrates strong adherence to secure coding practices regarding database interactions, utilizing prepared statements exclusively and performing capability checks and nonce checks at its entry points. The lack of known CVEs and recorded vulnerabilities is also a significant strength, suggesting a generally stable and well-maintained codebase.
However, several areas raise concern. The presence of the "create_function" dangerous function is a red flag, as it can be a vector for code injection if not handled with extreme care and proper sanitization, though the absence of taint analysis flows in this report means we cannot confirm its exploitability. More significantly, the analysis indicates that 50% of output operations are not properly escaped. This is a critical weakness that opens the door to Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into the website. The single shortcode, while having an entry point, is not explicitly flagged as unprotected, but the lack of output escaping for its rendered content is a serious risk.
In conclusion, while "yy-events" v1.4 has a solid foundation in database security and access control, the widespread lack of output escaping and the presence of a dangerous function represent significant vulnerabilities that need immediate attention. The absence of recorded historical vulnerabilities is positive but does not negate the current code analysis findings. Addressing the XSS risk is paramount.
Key Concerns
- Dangerous function found (create_function)
- 50% of outputs are not properly escaped
YY EVENTS Security Vulnerabilities
YY EVENTS Release Timeline
YY EVENTS Code Analysis
Dangerous Functions Found
Output Escaping
YY EVENTS Attack Surface
Shortcodes 1
WordPress Hooks 14
Maintenance & Trust
YY EVENTS Maintenance & Trust
Maintenance Signals
Community Trust
YY EVENTS Alternatives
SportsPress – Sports Club & League Manager
sportspress
SportsPress is an extendable all-in-one sports data plugin that helps sports clubs set up and manage a league or club site quickly and easily.
Bandsintown Events
bandsintown
Bandsintown's Events plugin for displaying your upcoming events.
Songkick Concerts and Festivals
songkick-concerts-and-festivals
This plugin lets you display events for a Songkick user, artist, venue, or metro area on your WordPress blog, as a widget or shortcode.
Detailed Player Stats for SportsPress
detailed-player-stats-for-sportspress
Show the individual stats and performances of each event for a player per season.
Simple Event Summary for SportsPress
simple-event-summary-for-sportspress
The Simple Event Summary for SportsPress plugin enhances your SportsPress plugin by adding a brief event summary below the main event card.
YY EVENTS Developer Profile
1 plugin · 20 total installs
How We Detect YY EVENTS
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yy-events/css/style.css/wp-content/plugins/yy-events/js/script.js/wp-content/plugins/yy-events/js/script.jsyy-events/css/style.css?ver=yy-events/js/script.js?ver=HTML / DOM Fingerprints
yye_date_controlyye_todayyye_beforeyye_nextyye_nowyye_calendaryyeBoxyyeHead+9 moreeyye_get_calendar<div class="yyeBox"><div class="yyeHead"><p class="yyeDate"><p class="yyeCatch">