Running WordPress? There’s now a WordPress-native version — WebCalendar for WordPress — that installs as a plugin instead of a separate PHP application, with full recurring-event support, iCal import/export, and a built-in holiday library. It’s free on WordPress.org, and there’s an overview here on k5n.us. The standalone PHP application on this page is still maintained and is not going away.
Table of Contents
About WebCalendar
WebCalendar is a PHP-based calendar application that can be configured as a single-user calendar, a multi-user calendar for groups of users, or as an event calendar viewable by visitors. MySQL/MariaDB, SQLite3, PostgreSQL, Oracle, DB2, Interbase, MS SQL Server, or ODBC is required. The version 1.9.X releases are still a little rough around the edges since these include an overhaul of the UI to use Bootstrap and jQuery and a complete rewrite of the web-based installer.
WebCalendar can be setup in a variety of ways, such as…
- A schedule management system for a single person
- A schedule management system for a group of people, allowing one or more assistants to manage the calendar of another user
- An events schedule that anyone can view, allowing visitors to submit new events
- A calendar server that can be viewed with iCalendar-compliant calendar applications like Mozilla Sunbird, Apple iCal or GNOME Evolution or RSS-enabled applications like Firefox, Thunderbird, RSSOwl, FeedDemon, or BlogExpress.
Overview of Features
- Multi-user support
- 30 supported languages: Basque, Bulgarian, Chinese-Big5, Chinese-GB2312, Czech, Danish, Dutch, English-US, Estonian, Finnish, French, Galician, German, Greek, Holo-Big5, Hungarian, Icelandic, Italian, Japanese, Korean, Norwegian, Polish, Portuguese_BR, Portuguese, Romanian, Russian, Spanish, Swedish, Turkish, Welsh (see current list of translations here)
- Web-based installer
- Auto-detect user’s language preference from browser settings
- View calendars by day, week, month or year
- View another user’s calendar
- View one or more users’ calendar via layers on top of your own calendar
- Add/Edit/Delete users
- Add/Edit/Delete events
- Repeating events including support for overriding or deleting (exceptions)
- Configurable custom event fields
- User-configurable preferences for colors, 12/24 time format, Sun/Mon week start
- Checks for scheduling conflicts
- Email reminders for upcoming events
- Email notifications for new/updated/deleted events
- Export events to iCalendar
- Import from iCalendar/ics format
- Optional general access (no login required) to allow calendar to be viewed by people without a login (useful for event calendars)
- Users can make their calendar available publicly to anyone with an iCalendar-compliant calendar program (such as Apple’s iCal, Mozilla Calendar or Sunbird)
- Publishing of free/busy schedules (part of the iCalendar standard)
- RSS support that puts a user’s calendar into RSS
- Subscribe to “remote” calendars (hosted elsewhere on the net) in either iCalendar or hCalendar formats (WebCalendar 1.1+)
- User authentication: Web-based, HTTP, LDAP or NIS
System Requirements
- PHP 8 or later
- PHP support and access to one of the following databases:
- SQLite
- MySQL/MariaDB
- Oracle
- Postgres
- IBM DB2
- Access to cron for Linux/Unix systems (to send out reminders)
Development Cost
The following metrics from Ohloh show how much it would have cost to commercially develop WebCalendar.
- Codebase Size: 138,588 lines
- Estimated Effort: 34 person-years
- Estimated Cost: $1,884,469
- (As of 11 August 2024)
Donations
If you’d like to help support the costs of developing, maintaining and supporting WebCalendar, please consider donating.
Developer Resources
- Github page for WebCalendar:
- Issues
- Pull requests
- Wiki
- Download the development code as a zip file
License
WebCalendar is available under the GNU General Public License, version 2.
For more information on this license:
Documentation
- System Administrator’s Guide
Introduction, installation instructions and FAQ - UPGRADING (WebCalendar 1.3.0)
Provides instruction on upgrading to version 1.3.7 from an older version - Database Design (WebCalendar 1.3.0)
Version 1.2.7 database schema
Most Recent Changes
Below are the most recent source code commits to github on the master branch.
- Merge pull request #798 from craigk5n/fix/js-cacher-path-traversalby craigk5n on October 5, 2026 at 6:54 pm
Merge pull request #798 from craigk5n/fix/js-cacher-path-traversal Security release v1.9.25: js_cacher.php file inclusion and XSS
- test: run the availability test without serializing globalsby craigk5n on October 5, 2026 at 6:43 pm
test: run the availability test without serializing globals Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- chore(release): v1.9.25by craigk5n on October 5, 2026 at 6:43 pm
chore(release): v1.9.25 Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- fix: request values reached script src and JS unescaped via js_cacherby craigk5n on October 5, 2026 at 5:44 pm
fix: request values reached script src and JS unescaped via js_cacher catsel.php and availability.php pass request values (form name, date) to print_header() as js_cacher.php path segments, and print_header() wrote them raw into <script src=”…”>. A quote closed the attribute, so catsel.php?form=x” onload=alert(1) ran script for a logged-in user. includes/js/catsel.php and availability.php then echoed the same values as bare JavaScript. js_cacher_src() now URL-encodes each segment; catsel.php emits its form name only when it is an identifier; availability.php casts the date to ints and restricts the form name the same way. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
- fix: js_cacher.php included any file on the server, unauthenticatedby craigk5n on October 5, 2026 at 5:26 pm
fix: js_cacher.php included any file on the server, unauthenticated js_cacher.php checked only that inc began with “js/”, then appended every later segment, “..” included, to the path it passed to include_once. Its other gate compared the second segment against readdir() of includes/js, which lists “.” and “..”, so inc=js/../../../../../etc/passwd returned /etc/passwd with no login, and any readable PHP file on the box could be executed. Only a file directly inside includes/js is included now. Later segments stay available in $arinc as the arguments catsel.php and availability.php read, but are never part of the path. The dead htmlarea branch is removed; that directory no longer exists. Reported by github.com/dutchypoo. Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
Download Metrics
- Downloads via Github: 21379
- Downloads via SourceForge: 1417991
Related Links
- Standards
- Calendar client applications – You can use the applications to view events stored in WebCalendar if you enable its publishing settings.
- iCalendar/ics download sites – These sites contain calendars for holidays, sports teams schedules, music converts, etc. You can import these files into WebCalendar.
- iCalShare
- Apple iCal Library
- DateDex
- Project24: holiday and weather calendars