
Sign In Scheduling Online Appointment Booking System Security & Risk Analysis
wordpress.org/plugins/10to8-online-bookingEmbed online appointment scheduling from Sign In Scheduling directly into your WordPress site.
Is Sign In Scheduling Online Appointment Booking System Safe to Use in 2026?
Generally Safe
Score 92/100Sign In Scheduling Online Appointment Booking System has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of the '10to8-online-booking' plugin v1.1.0 reveals a generally good security posture concerning direct code vulnerabilities. There are no identified dangerous functions, raw SQL queries, unescaped output, file operations, or external HTTP requests in the analyzed code. The plugin also demonstrates a lack of critical or high-severity taint flows, suggesting that data handling within the code is likely sanitized. However, the complete absence of nonce checks and capability checks across all entry points is a significant concern. While there are no unprotected AJAX handlers or REST API routes, relying solely on WordPress's default access control without explicit checks in the plugin's own code can leave it vulnerable to various privilege escalation or unauthorized action attacks if an attacker can trick a logged-in user into triggering these actions.
The vulnerability history indicates that the plugin has had one known CVE, specifically a Cross-Site Scripting (XSS) vulnerability, which was patched prior to the current version. The fact that there are no currently unpatched vulnerabilities and that the past vulnerability was of medium severity is a positive sign. However, the presence of a past XSS vulnerability, even if patched, highlights a potential area of weakness. The absence of any capability checks on the identified shortcode is also a point of concern, as shortcodes can be an entry point for user interaction and potential exploitation if not properly secured. While the overall code analysis shows good practices, the lack of explicit security checks on its entry points and the history of an XSS vulnerability warrant careful consideration of potential risks.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- Shortcode without explicit capability check
- Past XSS vulnerability (medium severity)
Sign In Scheduling Online Appointment Booking System Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
10to8 Online Appointment Booking System <= 1.0.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via shortcode
Sign In Scheduling Online Appointment Booking System Code Analysis
Sign In Scheduling Online Appointment Booking System Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Sign In Scheduling Online Appointment Booking System Maintenance & Trust
Maintenance Signals
Community Trust
Sign In Scheduling Online Appointment Booking System Alternatives
Appointment scheduling and Booking Manager
appointment-scheduling-and-booking-manager
Offer self-service online appointment scheduling by BuddyPress Members, and get more appointments in less time.
Tebuto – Online-Terminbuchung
tebuto-online-terminbuchung
Integriere die Online-Terminbuchung von Tebuto in deine WordPress-Website. Biete öffentliche Termine direkt auf deiner Seite an.
Appointment Bookings for Zoom GoogleMeet and more – Wappointment
wappointment
Get clients to quickly book a meeting with you by Zoom, GoogleMeet, phone or at your office
Cal.com
cal-com
Embed Cal.com booking calendar in WordPress.
SuperSaaS – online appointment scheduling
supersaas-appointment-scheduling
SuperSaaS is a flexible appointment scheduling system that works with many different businesses. The basic version is free.
Sign In Scheduling Online Appointment Booking System Developer Profile
1 plugin · 800 total installs
How We Detect Sign In Scheduling Online Appointment Booking System
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/10to8-online-booking/init.jshttps://d3saea0ftg7bjt.cloudfront.net/embed/js/embed.min.js/wp-content/plugins/10to8-online-booking/init.jsHTML / DOM Fingerprints
wordpressZembedConfig<div id="TTE-</div>