
Travel & Tours Meta Search Security & Risk Analysis
wordpress.org/plugins/adiaha-hotelGDS & OTA go-LIVE Solution - Amadeus, Travelport (Galileo), Hotelbeds, TBO, Rezlive, Restel and 150+ integrated suppliers.
Is Travel & Tours Meta Search Safe to Use in 2026?
Mostly Safe
Score 78/100Travel & Tours Meta Search is generally safe to use. 1 past CVE were resolved. Keep it updated.
The adiaha-hotel plugin v3.1 exhibits several concerning security weaknesses, particularly in its handling of user input and authorization. The static analysis reveals a significant attack surface with 15 entry points, of which 4 are unprotected AJAX handlers. This lack of authorization checks on a substantial portion of its entry points is a major red flag. Furthermore, the plugin fails to implement any capability checks or nonce verification for these handlers, making them susceptible to unauthorized access and potential exploitation. The absence of prepared statements for its single SQL query and the complete lack of output escaping for its two identified outputs are also serious concerns, potentially leading to SQL injection and cross-site scripting vulnerabilities, respectively. The vulnerability history shows one known medium-severity CVE, which remains unpatched. This historical pattern, combined with the current code analysis findings, suggests a recurring issue with missing authorization and a general disregard for secure coding practices. While the absence of dangerous functions, file operations, and critical taint flows is positive, these strengths are overshadowed by the numerous critical weaknesses in authorization, input sanitization, and output escaping. The overall security posture is poor, and immediate attention is required to address these vulnerabilities.
Key Concerns
- Unprotected AJAX handlers
- SQL queries without prepared statements
- Unescaped output
- No nonce checks
- No capability checks
- Unpatched medium CVE
Travel & Tours Meta Search Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Flights & Hotels Booking WP Plugin <= 3.1 - Missing Authorization
Travel & Tours Meta Search Code Analysis
SQL Query Safety
Output Escaping
Travel & Tours Meta Search Attack Surface
AJAX Handlers 4
Shortcodes 11
WordPress Hooks 3
Maintenance & Trust
Travel & Tours Meta Search Maintenance & Trust
Maintenance Signals
Community Trust
Travel & Tours Meta Search Alternatives
OzonTravel: Flights,Hotels,Railways,Insurance
ozontravelwidget
Travel tools to find flights, hotels, railways and insurance.
Priceline Partner Network WordPress Plugin
priceline-partner-network-official-searchbox
Easily add the Priceline travel widget to your own website in just a few clicks.
WP Tripadvisor Review Widgets
review-widgets-for-tripadvisor
Embed Tripadvisor reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Tripadvisor reviews.
Booking.com Official Search Box
bookingcom-official-searchbox
The official Booking.com search box is a user-friendly, customisable plugin to add the Booking.com search box to your own website in two easy steps.
DSGVO/GDPR Cookies, DSE, Impressum & Google Fonts Proxy
dsgvo-de
DSGVO konforme Cookie Hinweise, Datenschutzerklärung, Google Analytics und Google Fonts Lösung
Travel & Tours Meta Search Developer Profile
1 plugin · 400 total installs
How We Detect Travel & Tours Meta Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/adiaha-hotel/asset/images/icon.png//www.abengines.com/ui/HTML / DOM Fingerprints
setupguidesetup-dialogsetup-contentsetup-bodysetup-bodyimgsetup-body1setup-body2setup-body3+5 moredata-piddata-apikey[travon_searchBox][travon_searchResults]