Awesome Hotel Booking Security & Risk Analysis

wordpress.org/plugins/awesome-hotel-booking

The most comprehensive, high-performance car rental engine for WordPress. Total control over your fleet, bookings, revenue, and customer experience.

0 active installs v1.0.3 PHP 7.4+ WP 5.8+ Updated Jan 10, 2026
car-bookingcar-rentalcar-rental-crmrental-historyvehicle-booking
99
A · Safe
CVEs total1
Unpatched0
Last CVEJan 6, 2026
Download
Safety Verdict

Is Awesome Hotel Booking Safe to Use in 2026?

Generally Safe

Score 99/100

Awesome Hotel Booking has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jan 6, 2026Updated 2mo ago
Risk Assessment

The "awesome-hotel-booking" v1.0.3 plugin exhibits a generally strong security posture, primarily due to its diligent implementation of prepared statements for all SQL queries, extensive output escaping (93%), and a robust number of nonce and capability checks. The static analysis reveals a moderate attack surface consisting of AJAX handlers and shortcodes, but importantly, all identified entry points appear to have authorization checks, indicating good practice in this area. There are no reported critical or high-severity vulnerabilities in its history, and the single medium-severity vulnerability from 2026 has been patched. The taint analysis also shows no critical or high-severity flows, with only a small number of unsanitized paths, which are not deemed critical according to the provided severity levels.

However, a few areas warrant attention. The presence of 4 unsanitized paths in the taint analysis, even if not critical, represents a potential area for future exploitation if context or severity is misjudged. While the overall output escaping is high, the 7% of outputs that are not properly escaped could become a vector for Cross-Site Scripting (XSS) vulnerabilities if sensitive data is involved. The vulnerability history, though currently clear, includes a past medium-severity vulnerability related to "Incorrect Authorization," suggesting a need for continued vigilance and rigorous security testing to prevent recurrence of authorization issues. Overall, the plugin demonstrates a commitment to security best practices, but the minor issues identified in taint analysis and output escaping, along with the historical vulnerability, suggest that ongoing maintenance and careful updates are crucial.

Key Concerns

  • Unsanitized paths in taint analysis
  • Unescaped output percentage (7%)
  • Past medium severity vulnerability (Incorrect Authorization)
Vulnerabilities
1

Awesome Hotel Booking Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-14352medium · 5.3Incorrect Authorization

Awesome Hotel Booking <= 1.0.3 - Incorrect Authorization to Unauthenticated Arbitrary Booking Modification

Jan 6, 2026 Patched in 1.0.4 (7d)
Code Analysis
Analyzed Mar 17, 2026

Awesome Hotel Booking Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
6 prepared
Unescaped Output
55
751 escaped
Nonce Checks
23
Capability Checks
10
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared6 total queries

Output Escaping

93% escaped806 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

25 flows4 with unsanitized paths
ahbn_main_page (awesome-hotel-booking.php:76)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Awesome Hotel Booking Attack Surface

Entry Points12
Unprotected0

AJAX Handlers 4

noprivwp_ajax_ahbn_ajax_loginfrontend\login\ahbn-frontend-login.php:9
noprivwp_ajax_ahbn_ajax_registerfrontend\registration\ahbn-frontend-register.php:12
authwp_ajax_ahbn_save_bookingfrontend\single\ahbn-frontned-room-single.php:24
noprivwp_ajax_ahbn_save_bookingfrontend\single\ahbn-frontned-room-single.php:25

Shortcodes 8

[ahbn_account] frontend\account\ahbn-frontned-account.php:9
[ahbn_header_auth] frontend\auth\ahbn-frontend-auth.php:9
[ahbn_login] frontend\login\ahbn-frontend-login.php:45
[ahbn_register] frontend\registration\ahbn-frontend-register.php:69
[ahbn_all_rooms] frontend\rooms\ahbn-frontend-rooms.php:9
[ahbn_search_form] frontend\search\ahbn-frontend-search-form.php:8
[ahbn_room_details] frontend\single\ahbn-frontned-room-single.php:116
[ahbn_thanks_details] frontend\thanks\ahbn-frontned-thanks.php:5
WordPress Hooks 10
actionadmin_post_ahbn_delete_roomadmin\rooms\ahbn-room-delete.php:10
actioninitawesome-hotel-booking.php:27
actionadmin_menuawesome-hotel-booking.php:64
actionadmin_enqueue_scriptsawesome-hotel-booking.php:194
actionwp_enqueue_scriptsawesome-hotel-booking.php:208
actionadmin_initawesome-hotel-booking.php:220
actioninitawesome-hotel-booking.php:266
filterquery_varsawesome-hotel-booking.php:276
actioninitfrontend\single\ahbn-frontned-room-single.php:8
filterquery_varsfrontend\single\ahbn-frontned-room-single.php:16
Maintenance & Trust

Awesome Hotel Booking Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 10, 2026
PHP min version7.4
Downloads214

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Awesome Hotel Booking Developer Profile

Abdullah Nahian

12 plugins · 1K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
172 days
View full developer profile
Detection Fingerprints

How We Detect Awesome Hotel Booking

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/awesome-hotel-booking/assets/css/admin-style.css/wp-content/plugins/awesome-hotel-booking/assets/js/admin-script.js/wp-content/plugins/awesome-hotel-booking/assets/css/frontend-style.css/wp-content/plugins/awesome-hotel-booking/assets/js/frontend-script.js
Script Paths
/wp-content/plugins/awesome-hotel-booking/assets/js/admin-script.js/wp-content/plugins/awesome-hotel-booking/assets/js/frontend-script.js
Version Parameters
awesome-hotel-booking/assets/css/admin-style.css?ver=awesome-hotel-booking/assets/js/admin-script.js?ver=awesome-hotel-booking/assets/css/frontend-style.css?ver=awesome-hotel-booking/assets/js/frontend-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
awesome-hotel-bookingahbn-sidebar-containerahbn-brand-headerversion-tagahbn-left-tabsahbn-nav-labelahbn-right-box
Data Attributes
data-page-title
FAQ

Frequently Asked Questions about Awesome Hotel Booking