
AviaSales поиск авиабилетов Security & Risk Analysis
wordpress.org/plugins/aviasalesru-search-widgetПлагин Aviasales.ru для поиска билетов на вашем блоге.
Is AviaSales поиск авиабилетов Safe to Use in 2026?
Generally Safe
Score 85/100AviaSales поиск авиабилетов has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The aviasalesru-search-widget plugin v2.0.4 exhibits a mixed security posture. On the positive side, there are no identified CVEs, and the plugin demonstrates good practices regarding SQL query preparation, with all queries using prepared statements. Furthermore, the attack surface appears minimal, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected. Taint analysis also reveals no significant vulnerabilities.
However, significant concerns arise from the static code analysis. The presence of the `create_function` function is a clear indicator of potential security risks, as it can lead to arbitrary code execution if not handled with extreme care, especially if user-supplied data is involved. More critically, the fact that 0% of the 91 output points are properly escaped is a major vulnerability. This means that any dynamic content displayed by the plugin is susceptible to Cross-Site Scripting (XSS) attacks, allowing attackers to inject malicious scripts into users' browsers.
Given the absence of historical vulnerabilities and the limited attack surface, the plugin might not have been a target for exploitation. However, the identified code-level weaknesses, particularly the unescaped output and the use of `create_function`, present tangible security risks that could be exploited if a suitable attack vector were discovered or created. The plugin's strengths lie in its SQL handling and limited entry points, but these are overshadowed by the critical unescaped output issue and the risky use of `create_function`.
Key Concerns
- 0% output properly escaped
- Use of dangerous function: create_function
- Missing nonce checks
- Missing capability checks
AviaSales поиск авиабилетов Security Vulnerabilities
AviaSales поиск авиабилетов Code Analysis
Dangerous Functions Found
Output Escaping
AviaSales поиск авиабилетов Attack Surface
WordPress Hooks 1
Maintenance & Trust
AviaSales поиск авиабилетов Maintenance & Trust
Maintenance Signals
Community Trust
AviaSales поиск авиабилетов Alternatives
Travel Search
travel-search
Search and Compare major travel websites for cheapest flights, hotels, car rentals and vacation packages in this one-step travel search engine.
Online Pre-Travel Shopping
online-pre-travel-shopping
shopnfly is the first ever online, pre-travel shopping experience, creating a one-stop-shop for anything you might like to buy across an international …
Plugin Jetradar Cheap Flights
plugin-jetradar-cheap-flights
Find and book cheap flights with this useful flight search plugin from Jetradar.com.
MapGeo – Interactive Geo Maps
interactive-geo-maps
Create interactive vector maps of the world, continents, any country in the world and specific regions, including individual US state county maps.
WP Travel Engine – Tour Booking Plugin – Tour Operator Software
wp-travel-engine
WP Travel Engine is the most popular tour and travel booking WordPress plugin. Used by over 20,000 travel agency websites.
AviaSales поиск авиабилетов Developer Profile
1 plugin · 60 total installs
How We Detect AviaSales поиск авиабилетов
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/aviasalesru-search-widget/assets/minicolors/jquery.minicolors.js/wp-content/plugins/aviasalesru-search-widget/assets/minicolors/jquery.minicolors.css/wp-content/plugins/aviasalesru-search-widget/assets/aviasales_admin.js/wp-content/plugins/aviasalesru-search-widget/assets/aviasales_admin.css/wp-content/plugins/aviasalesru-search-widget/assets/jquery.ui.all.min.css/wp-content/plugins/aviasalesru-search-widget/assets/aviasales.css/wp-content/plugins/aviasalesru-search-widget/assets/pure_min.js/wp-content/plugins/aviasalesru-search-widget/assets/underscore-min.js+1 morehttp://nano.aviasales.ru/assets/autocomplete_places_http://nano.aviasales.ru/assets/minimal/inline_form.jsaviasalesru-search-widget/assets/minicolors/jquery.minicolors.js?ver=aviasalesru-search-widget/assets/minicolors/jquery.minicolors.css?ver=aviasalesru-search-widget/assets/aviasales_admin.js?ver=aviasalesru-search-widget/assets/aviasales_admin.css?ver=aviasalesru-search-widget/assets/jquery.ui.all.min.css?ver=aviasalesru-search-widget/assets/aviasales.css?ver=aviasalesru-search-widget/assets/pure_min.js?ver=aviasalesru-search-widget/assets/underscore-min.js?ver=aviasalesru-search-widget/assets/aviasales.js?ver=HTML / DOM Fingerprints
aviasales_logo<!-- Aviasales widget error: need affiliate id! -->id_baseaffiliate_idwidget_langshow_logowidget_titletitle_color+6 morewindow.Aviasales