Travel & Tours Meta Search Security & Risk Analysis

wordpress.org/plugins/adiaha-hotel

GDS & OTA go-LIVE Solution - Amadeus, Travelport (Galileo), Hotelbeds, TBO, Rezlive, Restel and 150+ integrated suppliers.

400 active installs v3.1 PHP + WP 3.4.0+ Updated Nov 13, 2025
flightsgalileogdshotelstravelport
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVESep 30, 2025
Safety Verdict

Is Travel & Tours Meta Search Safe to Use in 2026?

Mostly Safe

Score 78/100

Travel & Tours Meta Search is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Sep 30, 2025Updated 4mo ago
Risk Assessment

The adiaha-hotel plugin v3.1 exhibits several concerning security weaknesses, particularly in its handling of user input and authorization. The static analysis reveals a significant attack surface with 15 entry points, of which 4 are unprotected AJAX handlers. This lack of authorization checks on a substantial portion of its entry points is a major red flag. Furthermore, the plugin fails to implement any capability checks or nonce verification for these handlers, making them susceptible to unauthorized access and potential exploitation. The absence of prepared statements for its single SQL query and the complete lack of output escaping for its two identified outputs are also serious concerns, potentially leading to SQL injection and cross-site scripting vulnerabilities, respectively. The vulnerability history shows one known medium-severity CVE, which remains unpatched. This historical pattern, combined with the current code analysis findings, suggests a recurring issue with missing authorization and a general disregard for secure coding practices. While the absence of dangerous functions, file operations, and critical taint flows is positive, these strengths are overshadowed by the numerous critical weaknesses in authorization, input sanitization, and output escaping. The overall security posture is poor, and immediate attention is required to address these vulnerabilities.

Key Concerns

  • Unprotected AJAX handlers
  • SQL queries without prepared statements
  • Unescaped output
  • No nonce checks
  • No capability checks
  • Unpatched medium CVE
Vulnerabilities
1

Travel & Tours Meta Search Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-62916medium · 5.3Missing Authorization

Flights & Hotels Booking WP Plugin <= 3.1 - Missing Authorization

Sep 30, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Travel & Tours Meta Search Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
2
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

0% escaped2 total outputs
Attack Surface
4 unprotected

Travel & Tours Meta Search Attack Surface

Entry Points15
Unprotected4

AJAX Handlers 4

authwp_ajax_deleteUsertravon.php:250
authwp_ajax_addUsertravon.php:251
authwp_ajax_addUsertravon.php:268
noprivwp_ajax_addUsertravon.php:269

Shortcodes 11

[adivaha_ds_HotelDescription] includes\shortCode.php:15
[adivaha_ds_HotelRating] includes\shortCode.php:25
[adivaha_ds_HotelReview] includes\shortCode.php:35
[adivaha_ds_HotelPointofInterest] includes\shortCode.php:45
[adivaha_ds_HotelCheckInInstructions] includes\shortCode.php:55
[adivaha_ds_HotelAmeneties] includes\shortCode.php:75
[adivaha_ds_HotelImages] includes\shortCode.php:128
[adivaha_ds_HotelMap] includes\shortCode.php:142
[adivaha_ds_TripAdvisorReview] includes\shortCode.php:153
[travon_searchBox] travon.php:76
[travon_searchResults] travon.php:77
WordPress Hooks 3
actionadmin_bar_menutravon.php:60
actionadmin_menutravon.php:62
actioninittravon.php:176
Maintenance & Trust

Travel & Tours Meta Search Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedNov 13, 2025
PHP min version
Downloads20K

Community Trust

Rating82/100
Number of ratings17
Active installs400
Developer Profile

Travel & Tours Meta Search Developer Profile

Travon WP

1 plugin · 400 total installs

79
trust score
Avg Security Score
78/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Travel & Tours Meta Search

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/adiaha-hotel/asset/images/icon.png
Script Paths
//www.abengines.com/ui/

HTML / DOM Fingerprints

CSS Classes
setupguidesetup-dialogsetup-contentsetup-bodysetup-bodyimgsetup-body1setup-body2setup-body3+5 more
Data Attributes
data-piddata-apikey
Shortcode Output
[travon_searchBox][travon_searchResults]
FAQ

Frequently Asked Questions about Travel & Tours Meta Search