Booking System – bok.to Security & Risk Analysis

wordpress.org/plugins/booking-system-bok-to

Add booking button or booking widget to your website, manage your product list and start receiving bookings from your clients.

0 active installs v1.0.1 PHP 7.1+ WP 5.6.1+ Updated Feb 25, 2021
booking-page-generatorbookingsbookings-pageonline-appointmentsscheduling-website
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Booking System – bok.to Safe to Use in 2026?

Generally Safe

Score 85/100

Booking System – bok.to has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "booking-system-bok-to" plugin v1.0.1 exhibits a mixed security posture. On the positive side, the plugin has a very small attack surface with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are exposed without authentication or permission checks. The taint analysis also shows no critical or high-severity flows with unsanitized paths, which is a very strong indicator of good sanitization practices for user-supplied input that could lead to injection attacks. Additionally, the vast majority of output escaping is properly handled and there are no known vulnerabilities in its history.

However, there are significant concerns that temper this positive assessment. The most prominent issue is the use of raw SQL queries without prepared statements. With 27 total SQL queries and 0% utilizing prepared statements, this presents a substantial risk of SQL injection vulnerabilities. While the taint analysis didn't find any directly exploitable flows, the lack of prepared statements means that if any user-supplied data is ever used within these queries without proper sanitization and escaping, an attacker could potentially manipulate the database. Furthermore, the complete absence of nonce checks on the entry points, though limited in number, is a weakness that could be exploited in conjunction with other vulnerabilities or social engineering tactics. The presence of file operations and external HTTP requests also warrants careful review, although their specific contexts are not detailed here.

Key Concerns

  • Raw SQL queries without prepared statements
  • Missing nonce checks
Vulnerabilities
None known

Booking System – bok.to Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Booking System – bok.to Code Analysis

Dangerous Functions
0
Raw SQL Queries
27
0 prepared
Unescaped Output
4
76 escaped
Nonce Checks
0
Capability Checks
1
File Operations
2
External Requests
10
Bundled Libraries
0

SQL Query Safety

0% prepared27 total queries

Output Escaping

95% escaped80 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
bokto_appointment_info (includes\calendar.php:391)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Booking System – bok.to Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_enqueue_scriptsbok_sys.php:133
actionadmin_enqueue_scriptsbok_sys.php:134
actionadmin_menubok_sys.php:135
actionwp_enqueue_scriptsbok_sys.php:139
actionwp_footerincludes\menu_or_widget.php:68
actionwp_footerincludes\menu_or_widget.php:72
actionwp_footerincludes\menu_or_widget.php:73
Maintenance & Trust

Booking System – bok.to Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedFeb 25, 2021
PHP min version7.1
Downloads991

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

Booking System – bok.to Developer Profile

getreveltd

2 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Booking System – bok.to

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/booking-system-bok-to/admin/css/style.css/wp-content/plugins/booking-system-bok-to/admin/js/service-type.js/wp-content/plugins/booking-system-bok-to/admin/css/public.css/wp-content/plugins/booking-system-bok-to/admin/js/find_button_place.js
Version Parameters
booking-system-bok-to/admin/css/style.css?ver=booking-system-bok-to/admin/js/service-type.js?ver=booking-system-bok-to/admin/css/public.css?ver=booking-system-bok-to/admin/js/find_button_place.js?ver=

HTML / DOM Fingerprints

CSS Classes
miniorders-widget-wrapperminiorders-widget-tabminiorders-widget-tab-nameminiorders-iframeminiorders-widget-closeminiorders-widget-close-img
Data Attributes
data-miniorders-widget-url
JS Globals
miniordersStartWidget
FAQ

Frequently Asked Questions about Booking System – bok.to