AffiliateWP – Booking Calendar Security & Risk Analysis

wordpress.org/plugins/awp-booking-calendar

Track referrals with Booking Calendar

0 active installs v1.0.1 PHP + WP 4.7.0+ Updated Unknown
affiliateawpbookingscalendarreferral
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is AffiliateWP – Booking Calendar Safe to Use in 2026?

Generally Safe

Score 100/100

AffiliateWP – Booking Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The awp-booking-calendar plugin, version 1.0.1, exhibits an exceptionally strong security posture based on the provided static analysis. The absence of any detected dangerous functions, raw SQL queries, file operations, external HTTP requests, or unescaped output is highly commendable and suggests adherence to secure coding practices. Furthermore, the lack of any known CVEs or recorded vulnerabilities in its history indicates a history of robust security maintenance.

However, the analysis reveals a significant lack of security checks for its limited attack surface. With zero AJAX handlers, REST API routes, shortcodes, or cron events, the plugin presents no obvious entry points for attackers. Critically, the analysis shows zero nonce checks and zero capability checks. While the current lack of entry points makes this less immediately risky, it creates a vulnerability for future development if new features are added without proper authentication and authorization mechanisms. The absence of any taint analysis results is also noteworthy, suggesting either a very small codebase or that the tools used did not identify any potential risks in the analyzed flows, which is a positive sign.

In conclusion, awp-booking-calendar v1.0.1 demonstrates excellent security in its current implementation, with no active vulnerabilities or common security weaknesses. The absence of dangerous code and a clean vulnerability history are significant strengths. The primary area of concern, albeit a future-facing one, is the complete lack of any authorization or nonce checks, which could become a critical weakness if the plugin's functionality expands without the introduction of these essential security measures.

Key Concerns

  • Missing Nonce Checks
  • Missing Capability Checks
Vulnerabilities
None known

AffiliateWP – Booking Calendar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AffiliateWP – Booking Calendar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

AffiliateWP – Booking Calendar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
filteraffwp_integrationsaffiliate-wp-booking-calendar.php:16
filteraffwp_integration_classesaffiliate-wp-booking-calendar.php:25
actionaffwp_integrations_loadaffiliate-wp-booking-calendar.php:34
actionaffwp_referral_type_initaffiliate-wp-booking-calendar.php:42
filteraffwp_referral_reference_columnincludes\integrations\class-booking-calendar.php:25
Maintenance & Trust

AffiliateWP – Booking Calendar Maintenance & Trust

Maintenance Signals

WordPress version tested5.1.22
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

AffiliateWP – Booking Calendar Developer Profile

QFNetwork

6 plugins · 50 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AffiliateWP – Booking Calendar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/awp-booking-calendar/assets/js/admin.js/wp-content/plugins/awp-booking-calendar/assets/css/admin.css
Script Paths
/wp-content/plugins/awp-booking-calendar/assets/js/admin.js
Version Parameters
awp-booking-calendar/assets/js/admin.js?ver=awp-booking-calendar/assets/css/admin.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about AffiliateWP – Booking Calendar