The Canary Events Display

Description

The Canary Events Display is made for websites that want to display events from The Canary Events. It synchronizes event information into WordPress and renders it with responsive shortcodes or optional local event pages.

After an administrator configures an account email and API secret, the plugin can:

  • Test the authenticated API connection.
  • Synchronize new, updated, and removed events.
  • Optionally include events liked or saved by the connected account.
  • Run manual, full, or scheduled synchronization every 4, 8, 12, or 24 hours.
  • Download event posters to the WordPress Media Library instead of permanently hotlinking them.
  • Display synchronized events with [canary_events] in a Gutenberg Shortcode block or other shortcode-compatible area.
  • Open event cards on The Canary Events by default, or optionally use local synchronized event pages.
  • Display all synchronized attendance dates and times in HH:MM format.
  • Filter shortcode output by island, category, upcoming/past status, layout, columns, and other display options.
  • Optionally show a The Canary Events attribution as text, image, or text + image. Attribution is disabled by default.
  • Automatically display the plugin admin interface in English, Spanish, German, or French according to the current WordPress user language. Unsupported languages fall back to English.

The legacy [canary_artist_events] shortcode remains supported for existing sites.

External service

This plugin relies on the external The Canary Events service to retrieve event data. The service is operated by The Canary Events, the plugin author.

Service: The Canary Events

The plugin does not contact The Canary Events merely because it is activated. A site administrator must configure credentials and then test/synchronize the connection, or explicitly enable automatic synchronization.

When a connection test or synchronization runs, the plugin sends the following to https://thecanaryevents.com/json/canary-events/v1/events over HTTPS:

  • The configured account email in the X-CEM-User HTTP header.
  • The configured API secret in the X-CEM-Secret HTTP header.
  • The selected language (es, en, de, or fr).
  • Synchronization options such as liked=1, full=1, or event_id when the corresponding feature is used.
  • A custom User-Agent containing the plugin name and version. It does not include the WordPress site URL.

The API returns event information that the plugin stores in private WordPress records. If returned event data contains a remote poster URL, the plugin may make a separate HTTPS request from the WordPress server to that image host to download the poster into the Media Library. That remote host can receive standard request information such as the server IP address and HTTP headers.

Service policies:

Shortcode

Basic event grid:

[canary_events]

Four events in two columns:

[canary_events limit="4" columns="2"]

Compact list without images:

[canary_events layout="compact" show_image="no"]

Tenerife events only:

[canary_events island="tenerife"]

Past events only:

[canary_events show_only_past="yes" order="desc"]

Detailed cards:

[canary_events limit="8" columns="4" show_description="yes" description_length="120"]

Supported attributes include limit, columns, layout, show_past, show_only_past, show_image, show_category, show_location, show_date, show_time, show_price, show_description, description_length, button_text, order, island, category, and class.

When show_date="yes", all synchronized dates returned for the event are displayed. show_only_past="yes" takes precedence over show_past.

Local event pages

By default, event buttons open the original event page on The Canary Events.

A local URL such as /events/2195/event-slug.html can be selected from The Canary Events > Settings > Event Links.

Local event pages and optional The Canary Events attribution are independent settings. The plugin does not require a public credit or external link in order to use local event pages.

A local page can display the synchronized poster, full description, all synchronized dates, times, location, price, organizer information, and event links.

If local event URLs return 404 after activation or migration, open Settings > Permalinks and click Save Changes once to refresh rewrite rules.

Optional attribution

Frontend attribution is disabled by default. An administrator can explicitly enable it under The Canary Events > Settings.

When enabled, the administrator can choose:

  • Text
  • Image
  • Text + image

and Left, Center, or Right alignment. If several event shortcodes appear on the same page, the plugin keeps only the final enabled attribution visible.

Privacy

The account email is stored in the WordPress Options API. The API secret is encrypted at rest using Sodium secretbox when available, with OpenSSL AES-256-GCM as a fallback, using keys derived from WordPress authentication salts.

The plugin does not expose the API secret in frontend HTML, JavaScript, REST responses, or synchronization logs. The WordPress Privacy Guide receives suggested disclosure text describing the external API and poster-download behavior.

The plugin itself does not add analytics, advertising, tracking pixels, or telemetry.

Security

  • Manual actions require the manage_options capability and WordPress nonces.
  • API credentials are transmitted only over HTTPS.
  • Remote API and poster requests use the WordPress safe HTTP API.
  • API responses and HTTP status codes are validated before processing.
  • Temporary HTTP 429 and 5xx responses use controlled retry behavior.
  • Poster downloads are limited to supported image MIME types and a maximum of 8 MB.
  • Synchronized events use the remote event ID as the unique key to avoid duplicates.
  • A synchronization lock prevents overlapping synchronization runs.

Bundled assets

The bundled The Canary Events logo in assets/images/the-canary-events-logo.png is provided by The Canary Events and distributed with this plugin under GPLv2 or later.

Screenshots

Installation

  1. Install and activate The Canary Events Display.
  2. Open The Canary Events > Settings.
  3. Enter the The Canary Events account email and API secret.
  4. Choose the preferred API language and synchronization options.
  5. Click Save settings.
  6. Click Test connection. The test succeeds only when the API explicitly confirms authentication.
  7. Click Run full synchronization for the initial import.
  8. Add [canary_events] to a page using a Gutenberg Shortcode block.

Automatic synchronization is disabled by default. If enabled, saving settings schedules the selected WordPress cron interval and queues an immediate background check.

The plugin admin interface follows the current WordPress user language for English, Spanish, German, and French. English is used as the fallback for every other WordPress user language. This interface language is separate from the Event Content Language setting used for API event data.

FAQ

Does the plugin contact an external service?

Yes. The connection test and synchronization features use The Canary Events API. See the External service section for exactly what is sent and links to the service policies.

Does it contact The Canary Events immediately after activation?

No. Automatic synchronization is off by default. An administrator must configure credentials and initiate a connection test/sync, or explicitly enable automatic synchronization.

Can I include liked or saved events?

Yes. Enable Liked / saved events in the plugin settings. Synchronization then includes liked=1 in the API request.

Is The Canary Events branding required?

No. Frontend attribution is optional and disabled by default. It is not required for local event pages or any other plugin feature.

Does the plugin create public WordPress posts for synchronized events?

It stores event records in a private custom post type. The plugin can expose sanitized local event detail pages through its dedicated /events/EVENT-ID/event-slug.html route.

What happens when an event is removed from the connected account?

It is removed from shortcode results and marked as removed locally. The plugin does not delete unrelated WordPress content.

Does uninstalling delete synchronized data?

Not by default. To remove plugin options and synchronized event records during uninstall, define TCEA_DELETE_DATA_ON_UNINSTALL as true before uninstalling. Media attachments are preserved to avoid deleting images used elsewhere.

Reviews

There are no reviews for this plugin.

Contributors & Developers

“The Canary Events Display” is open source software. The following people have contributed to this plugin.

Contributors

Changelog

1.0.19

  • Adds bundled English, Spanish, German and French interface language packs. The admin interface follows the WordPress user language and falls back to English for all other languages.
  • Moves the plugin to a top-level The Canary Events WordPress admin menu with Events, Settings, Documentation, and Log submenus.
  • Replaces the previous settings tabs with dedicated admin pages.
  • Redesigns the WordPress admin interface with a professional branded layout, connection tools, shortcode help, responsive controls and status cards.
  • Uses English as the default API content language for new installations and unsupported saved language values.

1.0.18

  • Resolves WordPress Plugin Check findings for file deletion, translator comments, admin request handling, deprecated translation loading, slow postmeta queries, and prefixed globals.
  • Adds a lightweight portal-ID lookup index to avoid unindexed postmeta lookups.

1.0.17

  • Keeps frontend attribution optional and disabled by default.
  • Removes the previous dependency between logo attribution and local event pages so plugin functionality is never conditional on displaying a public credit.
  • Keeps Open event on The Canary Events as the default event-link destination while allowing administrators to choose local event pages independently.
  • Removes unused admin JavaScript that previously enforced branding-dependent event links.
  • Hardens submission-readiness with explicit output escaping, sanitized secret input, rewrite cleanup on deactivation, and current WordPress 7.1 directory metadata.

For older release history, see changelog.txt.