BeBetterHotels Booking Form Security & Risk Analysis

wordpress.org/plugins/bebetterhotels-booking-form

Integrate The BeBetterHotels Search Engine with Wordpress to allow booking easily from your website.

20 active installs v1.0.14 PHP 7.4+ WP 5.2.0+ Updated Aug 8, 2024
appointmentbebetterhotelsbookingbooking-formreservations
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BeBetterHotels Booking Form Safe to Use in 2026?

Generally Safe

Score 92/100

BeBetterHotels Booking Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The overall security posture of the 'bebetterhotels-booking-form' plugin v1.0.14 appears to be strong based on the static analysis and vulnerability history. The absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and external HTTP requests are significant positives. The high percentage of properly escaped output further mitigates risks of cross-site scripting (XSS). The plugin also demonstrates good practice by having only one entry point, a shortcode, which has a capability check. The lack of any recorded CVEs, particularly critical or high severity ones, indicates a history of secure development or effective patching by the developers.

However, there are a few areas that warrant attention. The most notable is the complete absence of nonce checks. While the static analysis shows no direct AJAX handlers or REST API routes that are unprotected, the lack of nonces could still be a weakness if any of the functionality, particularly the shortcode, were to be invoked unexpectedly or maliciously. The taint analysis not finding any flows is reassuring, but this could also be a result of limited complexity in the plugin's code or the scope of the analysis itself. Given the otherwise clean report, the primary concern is the missing nonce implementation.

In conclusion, the 'bebetterhotels-booking-form' plugin exhibits a commendable security profile with robust protections against common web vulnerabilities. Its developers have prioritized secure coding practices like prepared statements and output escaping. The main weakness identified is the absence of nonce checks, which, while not directly exploitable in the current analysis, represents a potential gap in defending against certain types of attacks. The clean vulnerability history is a strong indicator of ongoing security consciousness.

Key Concerns

  • No nonce checks implemented
Vulnerabilities
None known

BeBetterHotels Booking Form Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

BeBetterHotels Booking Form Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
34 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

89% escaped38 total outputs
Attack Surface

BeBetterHotels Booking Form Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[bebetterhotels] bbh-booking-form.php:224
WordPress Hooks 6
actionplugins_loadedbbh-booking-form.php:32
actionadmin_initbbh-booking-form.php:48
actionadmin_menubbh-booking-form.php:63
actionadmin_enqueue_scriptsbbh-booking-form.php:131
actionwp_enqueue_scriptsbbh-booking-form.php:171
actionwp_enqueue_scriptsbbh-booking-form.php:172
Maintenance & Trust

BeBetterHotels Booking Form Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedAug 8, 2024
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

BeBetterHotels Booking Form Developer Profile

Fran

1 plugin · 20 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect BeBetterHotels Booking Form

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bebetterhotels-booking-form/assets/css/styles.css/wp-content/plugins/bebetterhotels-booking-form/assets/js/scripts.js
Script Paths
/wp-content/plugins/bebetterhotels-booking-form/assets/js/admin.js
Version Parameters
bebetterhotels-booking-form/assets/css/styles.css?ver=1.0.14bebetterhotels-booking-form/assets/js/scripts.js?ver=1.0.14bebetterhotels-booking-form/assets/js/admin.js?ver=1.0.14

HTML / DOM Fingerprints

CSS Classes
bbh-booking-form
Data Attributes
data-urldata-localedata-customerdata-adults_fielddata-childrens_fielddata-show_childrens+4 more
JS Globals
bbh_booking_form_params
Shortcode Output
<!-- BBH booking form -->
FAQ

Frequently Asked Questions about BeBetterHotels Booking Form