Book Doctor Appointments – iCliniq Security & Risk Analysis

wordpress.org/plugins/book-doctor-appointments-icliniq

This plugin uses https://www.icliniq.com 's doctor search API to list doctors in your website. Users can book doctor appointments directly from y …

10 active installs v1.0 PHP + WP 3.0+ Updated Jun 24, 2013
book-doctor-appointmentssidebarwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Book Doctor Appointments – iCliniq Safe to Use in 2026?

Generally Safe

Score 85/100

Book Doctor Appointments – iCliniq has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12yr ago
Risk Assessment

The 'book-doctor-appointments-icliniq' plugin v1.0 exhibits a mixed security posture. On one hand, it demonstrates good practices by having no known vulnerabilities in its history and by exclusively using prepared statements for its SQL queries. This indicates a potential awareness of common web vulnerabilities like SQL injection. However, significant concerns arise from the static analysis. The plugin has a complete lack of output escaping for all identified outputs, which presents a high risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, the taint analysis revealed two flows with unsanitized paths, which, although not classified as critical or high, still represent potential security weaknesses that could be exploited if data manipulation is possible.

The absence of any recorded CVEs or common vulnerability types is positive, suggesting the plugin has not historically been a significant security target or has been developed with reasonable care. However, the lack of vulnerability history can also sometimes indicate limited auditing or testing rather than inherent security. The presence of file operations without further context is a minor concern, as is the complete absence of nonce and capability checks, which, combined with the zero entry points without auth, could be a design choice but also leaves potential for future vulnerabilities if new entry points are added without proper security measures.

In conclusion, while the plugin avoids common pitfalls like raw SQL and known exploits, the critical deficiency in output escaping and the presence of unsanitized paths in taint analysis are substantial risks. The lack of any authentication checks on entry points, even though there are none currently, is a structural weakness that could lead to future security issues. Developers should prioritize implementing proper output sanitization to mitigate XSS risks.

Key Concerns

  • 0% output escaping
  • 2 unsanitized paths in taint analysis
  • 0 capability checks
  • 0 nonce checks
Vulnerabilities
None known

Book Doctor Appointments – iCliniq Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Book Doctor Appointments – iCliniq Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped26 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
icq_update_form (admin-page.php:12)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Book Doctor Appointments – iCliniq Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionwp_enqueue_scriptsbook-doctor-appointments-icliniq.php:41
actionadmin_initoptions.php:9
actionadmin_menuoptions.php:18
actionwidgets_initwidget.php:7
Maintenance & Trust

Book Doctor Appointments – iCliniq Maintenance & Trust

Maintenance Signals

WordPress version tested3.4.2
Last updatedJun 24, 2013
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Book Doctor Appointments – iCliniq Developer Profile

iCliniq

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Book Doctor Appointments – iCliniq

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/book-doctor-appointments-icliniq/css/style.css/wp-content/plugins/book-doctor-appointments-icliniq/js/custom.js
Script Paths
/wp-content/plugins/book-doctor-appointments-icliniq/js/custom.js
Version Parameters
book-doctor-appointments-icliniq/css/style.css?ver=book-doctor-appointments-icliniq/js/custom.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Book Doctor Appointments – iCliniq