Now that a new cross site scripting (XSS) vulnerability has been documented for this plugin, it's nearly certain that if you leave it installed you will eventually be hit. It's no longer supported by the author. There are other similar plugins. Switch to one that's actively maintained immediately.
http://packetstormsecurity.org/files/view/96787/evwp-xss.txt