Astro Booking Engine Security & Risk Analysis

wordpress.org/plugins/astro-booking-engine

Use shortcode [astro-booking-engine] to display the booking form. Configure with 5Stelle, Iperbooking, Passepartout, Simple booking, or Vertical booki …

10 active installs v1.4.0 PHP 7.4+ WP 5.2+ Updated Oct 31, 2025
booking-enginebooking-widgethotel-bookinghotel-booking-enginehotel-widget
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Astro Booking Engine Safe to Use in 2026?

Generally Safe

Score 100/100

Astro Booking Engine has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The 'astro-booking-engine' plugin version 1.4.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the robust use of prepared statements for SQL queries are significant strengths. Furthermore, the high percentage of properly escaped output and the lack of dangerous functions suggest diligent coding practices. The limited attack surface, consisting of a single shortcode, and the absence of external HTTP requests or file operations further contribute to its secure profile.

However, the static analysis does reveal a few areas that warrant attention. The most notable concern is the complete absence of nonce checks across all entry points. While the attack surface is small and there are no unprotected AJAX handlers or REST API routes, the lack of nonces leaves the shortcode vulnerable to Cross-Site Request Forgery (CSRF) attacks. Additionally, while the percentage of escaped output is high, the remaining 83% indicates that approximately 17% of output might not be properly escaped, potentially leading to Cross-Site Scripting (XSS) vulnerabilities, although no specific flows were identified in the taint analysis.

In conclusion, 'astro-booking-engine' v1.4.0 is largely well-secured, particularly with its avoidance of SQL injection and external threats. Its vulnerability history being clear is a positive indicator of past security efforts. The primary weaknesses lie in the missing CSRF protection via nonces and the slight concern regarding unescaped output. Addressing these specific points would significantly enhance its overall security.

Key Concerns

  • Missing nonce checks on entry points
  • Unescaped output (17% remaining)
Vulnerabilities
None known

Astro Booking Engine Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Astro Booking Engine Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
374
1826 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

83% escaped2200 total outputs
Attack Surface

Astro Booking Engine Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[astro-booking-engine] astro-booking-engine-common.php:222
WordPress Hooks 7
actionadmin_enqueue_scriptsastro-booking-engine-admin.php:51
actionadmin_initastro-booking-engine-admin.php:114
actionastro_plugin_panel_pagesastro-booking-engine-admin.php:121
actioninitastro-booking-engine.php:45
actioninitastro-booking-engine.php:53
actionwidgets_initincludes\classes\class-astro-booking-engine-widget.php:74
actionadmin_menuincludes\classes\class-astro-plugin-panel.php:16
Maintenance & Trust

Astro Booking Engine Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 31, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Astro Booking Engine Developer Profile

Mojtaba Amalian

5 plugins · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Astro Booking Engine

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/astro-booking-engine/css/astro-booking-engine.css/wp-content/plugins/astro-booking-engine/js/astro-booking-engine.js
Script Paths
/wp-content/plugins/astro-booking-engine/js/astro-booking-engine-/wp-content/plugins/astro-booking-engine/vendors/jquery-ui-themes/themes/
Version Parameters
astro-booking-engine/css/astro-booking-engine.css?ver=astro-booking-engine/js/astro-booking-engine.js?ver=astro-booking-engine/js/astro-booking-engine-

HTML / DOM Fingerprints

Data Attributes
astro_be_prefixastro_be_textdomain
JS Globals
ASTRO_BE_PREFIXASTRO_BE_TEXTDOMAIN
Shortcode Output
[astro-booking-engine]
FAQ

Frequently Asked Questions about Astro Booking Engine