Awesome Car Rental & Booking Security & Risk Analysis

wordpress.org/plugins/awesome-car-rental

The most comprehensive, high-performance car rental engine for WordPress. Total control over your fleet, bookings, revenue, and customer experience.

10 active installs v1.1.2 PHP 7.4+ WP 5.8+ Updated Jan 10, 2026
car-bookingcar-rentalcar-rental-crmrental-historyvehicle-booking
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Awesome Car Rental & Booking Safe to Use in 2026?

Generally Safe

Score 100/100

Awesome Car Rental & Booking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The "awesome-car-rental" plugin v1.1.2 demonstrates a generally strong security posture based on the provided static analysis. The absence of dangerous functions, file operations, and external HTTP requests is a positive indicator. Notably, all SQL queries are properly prepared, and a high percentage of output is correctly escaped, mitigating common injection and XSS risks. The presence of numerous nonce and capability checks on its entry points (AJAX handlers and shortcodes) suggests an effort to protect against unauthorized actions and cross-site request forgery. The plugin also has no recorded vulnerability history, which is a significant strength.

However, the taint analysis reveals a concern with 7 flows identified as having "unsanitized paths." While none are classified as critical or high severity, this indicates potential for path traversal or similar vulnerabilities if not handled meticulously. Although the overall number of entry points is relatively low, the presence of unsanitized paths is the most significant concern identified in the code. The bundled Freemius library, if outdated, could also present a latent risk, although its specific version is provided.

In conclusion, this plugin is commendably well-built with many security best practices implemented, particularly concerning SQL and output sanitization, and a clean vulnerability history. The primary area for improvement and vigilant monitoring is the resolution of the identified unsanitized path flows. The Freemius library should also be verified for its current security status.

Key Concerns

  • Unsanitized paths found in taint analysis
  • Bundled Freemius v1.0 library
Vulnerabilities
None known

Awesome Car Rental & Booking Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Awesome Car Rental & Booking Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
47
776 escaped
Nonce Checks
18
Capability Checks
8
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

94% escaped823 total outputs
Data Flows
7 unsanitized

Data Flow Analysis

25 flows7 with unsanitized paths
acrb_cars_tab (admin\cars\acrb-items-tabs.php:7)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Awesome Car Rental & Booking Attack Surface

Entry Points11
Unprotected0

AJAX Handlers 2

noprivwp_ajax_acrb_ajax_loginfrontend\login\acrb-frontend-login.php:10
noprivwp_ajax_acrb_ajax_registerfrontend\registration\acrb-frontend-register.php:13

Shortcodes 9

[acrb_account] frontend\account\acrb-frontned-account.php:8
[acrb_header_auth] frontend\auth\acrb-frontend-auth.php:8
[acrb_car_grid] frontend\cars\acrb-frontend-cars-grid.php:8
[acrb_all_cars] frontend\cars\acrb-frontend-cars.php:8
[acrb_login] frontend\login\acrb-frontend-login.php:48
[acrb_register] frontend\registration\acrb-frontend-register.php:71
[acrb_search_form] frontend\search\acrb-frontend-search-form.php:8
[acrb_single_car] frontend\single\acrb-frontned-car-single.php:346
[acrb_thanks] frontend\thanks\acrb-frontned-thanks.php:113
WordPress Hooks 9
actionadmin_post_acrb_delete_caradmin\cars\acrb-items-delete.php:8
actioninitawesome-car-rental.php:62
actionadmin_menuawesome-car-rental.php:85
actionadmin_enqueue_scriptsawesome-car-rental.php:218
actionwp_enqueue_scriptsawesome-car-rental.php:232
actionadmin_initawesome-car-rental.php:244
filterdisplay_post_statesawesome-car-rental.php:305
actionadmin_post_nopriv_acrb_submit_booking_actionfrontend\single\acrb-frontned-car-single.php:61
actionadmin_post_acrb_submit_booking_actionfrontend\single\acrb-frontned-car-single.php:62
Maintenance & Trust

Awesome Car Rental & Booking Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 10, 2026
PHP min version7.4
Downloads385

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Awesome Car Rental & Booking Developer Profile

Abdullah Nahian

12 plugins · 1K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
172 days
View full developer profile
Detection Fingerprints

How We Detect Awesome Car Rental & Booking

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/awesome-car-rental/admin/css/style.css/wp-content/plugins/awesome-car-rental/admin/js/main.js
Script Paths
/wp-content/plugins/awesome-car-rental/admin/js/main.js
Version Parameters
awesome-car-rental/admin/css/style.css?ver=awesome-car-rental/admin/js/main.js?ver=

HTML / DOM Fingerprints

CSS Classes
awesome-car-rentalafd-sidebar-containerafd-brand-headerafd-left-tabsafd-nav-labelafd-right-box
HTML Comments
<!-- FIX: Using sanitize_key( wp_unslash() ) to avoid Undefined Constant fatal error --><!-- FIX: Combined sanitization, unslashing, and nonce suppression for the sniffer --><!-- Handling status updates with the required translators comment format -->
Data Attributes
data-slugdata-tab-id
FAQ

Frequently Asked Questions about Awesome Car Rental & Booking