The Canary Events Display

The Canary Events Display

Details
View on WordPress

The Canary Events Display is made for websites that want to display events from The Canary Events. It synchronizes event information into WordPress and renders it with responsive shortcodes or optional local event pages.

After an administrator configures an account email and API secret, the plugin can:

  • Test the authenticated API connection.
  • Synchronize new, updated, and removed events.
  • Optionally include events liked or saved by the connected account.
  • Run manual, full, or scheduled synchronization every 4, 8, 12, or 24 hours.
  • Download event posters to the WordPress Media Library instead of permanently hotlinking them.
  • Display synchronized events with [canary_events] in a Gutenberg Shortcode block or other shortcode-compatible area.
  • Open event cards on The Canary Events by default, or optionally use local synchronized event pages.
  • Display all synchronized attendance dates and times in HH:MM format.
  • Filter shortcode output by island, category, upcoming/past status, layout, columns, and other display options.
  • Optionally show a The Canary Events attribution as text, image, or text + image. Attribution is disabled by default.

The legacy [canary_artist_events] shortcode remains supported for existing sites.

External service

This plugin relies on the external The Canary Events service to retrieve event data. The service is operated by The Canary Events, the plugin author.

Service: The Canary Events

The plugin does not contact The Canary Events merely because it is activated. A site administrator must configure credentials and then test/synchronize the connection, or explicitly enable automatic synchronization.

When a connection test or synchronization runs, the plugin sends the following to https://thecanaryevents.com/json/canary-events/v1/events over HTTPS:

  • The configured account email in the X-CEM-User HTTP header.
  • The configured API secret in the X-CEM-Secret HTTP header.
  • The selected language (es, en, de, or fr).
  • Synchronization options such as liked=1, full=1, or event_id when the corresponding feature is used.
  • A custom User-Agent containing the plugin name and version. It does not include the WordPress site URL.

The API returns event information that the plugin stores in private WordPress records. If returned event data contains a remote poster URL, the plugin may make a separate HTTPS request from the WordPress server to that image host to download the poster into the Media Library. That remote host can receive standard request information such as the server IP address and HTTP headers.

Service policies:

Shortcode

Basic event grid:

[canary_events]

Four events in two columns:

[canary_events limit="4" columns="2"]

Compact list without images:

[canary_events layout="compact" show_image="no"]

Tenerife events only:

[canary_events island="tenerife"]

Past events only:

[canary_events show_only_past="yes" order="desc"]

Detailed cards:

[canary_events limit="8" columns="4" show_description="yes" description_length="120"]

Supported attributes include limit, columns, layout, show_past, show_only_past, show_image, show_category, show_location, show_date, show_time, show_price, show_description, description_length, button_text, order, island, category, and class.

When show_date="yes", all synchronized dates returned for the event are displayed. show_only_past="yes" takes precedence over show_past.

Local event pages

By default, event buttons open the original event page on The Canary Events.

A local URL such as /events/2195/event-slug.html can be selected from Settings > Canary Events Display > Event links.

Local event pages and optional The Canary Events attribution are independent settings. The plugin does not require a public credit or external link in order to use local event pages.

A local page can display the synchronized poster, full description, all synchronized dates, times, location, price, organizer information, and event links.

If local event URLs return 404 after activation or migration, open Settings > Permalinks and click Save Changes once to refresh rewrite rules.

Optional attribution

Frontend attribution is disabled by default. An administrator can explicitly enable it under Settings > Canary Events Display.

When enabled, the administrator can choose:

  • Text
  • Image
  • Text + image

and Left, Center, or Right alignment. If several event shortcodes appear on the same page, the plugin keeps only the final enabled attribution visible.

Privacy

The account email is stored in the WordPress Options API. The API secret is encrypted at rest using Sodium secretbox when available, with OpenSSL AES-256-GCM as a fallback, using keys derived from WordPress authentication salts.

The plugin does not expose the API secret in frontend HTML, JavaScript, REST responses, or synchronization logs. The WordPress Privacy Guide receives suggested disclosure text describing the external API and poster-download behavior.

The plugin itself does not add analytics, advertising, tracking pixels, or telemetry.

Security

  • Manual actions require the manage_options capability and WordPress nonces.
  • API credentials are transmitted only over HTTPS.
  • Remote API and poster requests use the WordPress safe HTTP API.
  • API responses and HTTP status codes are validated before processing.
  • Temporary HTTP 429 and 5xx responses use controlled retry behavior.
  • Poster downloads are limited to supported image MIME types and a maximum of 8 MB.
  • Synchronized events use the remote event ID as the unique key to avoid duplicates.
  • A synchronization lock prevents overlapping synchronization runs.

Bundled assets

The bundled The Canary Events logo in assets/images/the-canary-events-logo.png is provided by The Canary Events and distributed with this plugin under GPLv2 or later.

Details

Plugin code:
the-canary-events-display
Plugin version:
1.0.18
Outdated:
No
WP version:
6.5 or higher
PHP version:
8.1 or higher
Test up to WP version:
7.1.3
Total installations:
0
Last updated:
2026-10-11
Rating:
Times rated:
0
api
canary-islands
events
gutenberg
shortcode