
AffiliateWP – Booking Calendar Security & Risk Analysis
wordpress.org/plugins/awp-booking-calendarTrack referrals with Booking Calendar
Is AffiliateWP – Booking Calendar Safe to Use in 2026?
Generally Safe
Score 100/100AffiliateWP – Booking Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The awp-booking-calendar plugin, version 1.0.1, exhibits an exceptionally strong security posture based on the provided static analysis. The absence of any detected dangerous functions, raw SQL queries, file operations, external HTTP requests, or unescaped output is highly commendable and suggests adherence to secure coding practices. Furthermore, the lack of any known CVEs or recorded vulnerabilities in its history indicates a history of robust security maintenance.
However, the analysis reveals a significant lack of security checks for its limited attack surface. With zero AJAX handlers, REST API routes, shortcodes, or cron events, the plugin presents no obvious entry points for attackers. Critically, the analysis shows zero nonce checks and zero capability checks. While the current lack of entry points makes this less immediately risky, it creates a vulnerability for future development if new features are added without proper authentication and authorization mechanisms. The absence of any taint analysis results is also noteworthy, suggesting either a very small codebase or that the tools used did not identify any potential risks in the analyzed flows, which is a positive sign.
In conclusion, awp-booking-calendar v1.0.1 demonstrates excellent security in its current implementation, with no active vulnerabilities or common security weaknesses. The absence of dangerous code and a clean vulnerability history are significant strengths. The primary area of concern, albeit a future-facing one, is the complete lack of any authorization or nonce checks, which could become a critical weakness if the plugin's functionality expands without the introduction of these essential security measures.
Key Concerns
- Missing Nonce Checks
- Missing Capability Checks
AffiliateWP – Booking Calendar Security Vulnerabilities
AffiliateWP – Booking Calendar Code Analysis
Output Escaping
AffiliateWP – Booking Calendar Attack Surface
WordPress Hooks 5
Maintenance & Trust
AffiliateWP – Booking Calendar Maintenance & Trust
Maintenance Signals
Community Trust
AffiliateWP – Booking Calendar Alternatives
Affiliate WP – Placeholder Variable
awp-placeholder-variable
Replace placeholder variable with tracking affiliate id
Affiliate WP – s2Member Pro Coupon Codes
awp-s2m-pro-cc
Track your AffiliateWP referrals using s2Member Pro Coupon Codes
Events Manager – Calendar, Bookings, Tickets, and more!
events-manager
Events calendar with bookings, scheduling, appointments, event registration, tickets, recurring events, and venue management.
Booking Calendar
booking
Original "Booking Calendar" plugin. Easily manage full-day bookings, time-slot appointments, or events in our all-in-one, outstanding booking system.
WP Simple Booking Calendar
wp-simple-booking-calendar
This booking calendar shows when something is booked or available. Use it to show when your holiday home is available for rent, for example.
AffiliateWP – Booking Calendar Developer Profile
6 plugins · 50 total installs
How We Detect AffiliateWP – Booking Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/awp-booking-calendar/assets/js/admin.js/wp-content/plugins/awp-booking-calendar/assets/css/admin.css/wp-content/plugins/awp-booking-calendar/assets/js/admin.jsawp-booking-calendar/assets/js/admin.js?ver=awp-booking-calendar/assets/css/admin.css?ver=