
Online Buchungssystem – edoobox Security & Risk Analysis
wordpress.org/plugins/booking-system-edooboxSimplify event and course management with Edoobox, an intuitive online booking system.
Is Online Buchungssystem – edoobox Safe to Use in 2026?
Generally Safe
Score 100/100Online Buchungssystem – edoobox has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "booking-system-edoobox" plugin version 3.4.1 exhibits a concerning security posture due to a significant number of unprotected AJAX entry points. While the static analysis did not reveal overtly dangerous functions or critical taint flows, the lack of authentication checks on all five identified AJAX handlers presents a substantial attack surface. This means an unauthenticated attacker could potentially interact with these endpoints, leading to unintended actions if the plugin's internal logic is not robustly designed.
The code analysis also indicates a low percentage of properly escaped output (20%), which could open the door to cross-site scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output without sufficient sanitization. The presence of file operations and external HTTP requests, while not inherently dangerous, increases the potential impact if an attacker can influence their behavior.
Notably, the plugin has a clean vulnerability history with zero recorded CVEs. This suggests that, historically, the developers may have had good security practices or that the plugin hasn't been a primary target for exploit development. However, the current static analysis findings, particularly the unprotected AJAX handlers and poor output escaping, highlight immediate areas of concern that outweigh the positive history. The plugin's strengths lie in its relatively low complexity in terms of static code signals like dangerous functions and SQL queries, but the identified entry points are a significant weakness.
Key Concerns
- 5 AJAX handlers without authentication checks
- Only 20% of outputs properly escaped
- 3 unsanitized taint flows (paths)
- 0 capability checks on entry points
Online Buchungssystem – edoobox Security Vulnerabilities
Online Buchungssystem – edoobox Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Online Buchungssystem – edoobox Attack Surface
AJAX Handlers 5
WordPress Hooks 21
Maintenance & Trust
Online Buchungssystem – edoobox Maintenance & Trust
Maintenance Signals
Community Trust
Online Buchungssystem – edoobox Alternatives
Beds24 Online Booking
beds24-online-booking
Accept commission free online bookings from your Wordpress website. Suitable for hotels, B&B's, holiday rentals, vacation rentals, apartments …
GreenRope Analytics
greenrope-analytics
Enables you to add GreenRope analytics and tracking to every page of your WordPress site.
MyBooking Reservation Engine
mybooking-reservation-engine
Mybooking Reservation Engine WordPress plugin.
Viking Bookings
viking-bookings
Easily embed booking forms from your Viking Bookings account on your WordPress site.
bookingkit
bookingkit
bookingkit allows you to easily make your events and tours bookable - instantly and directly on your website.
Online Buchungssystem – edoobox Developer Profile
1 plugin · 200 total installs
How We Detect Online Buchungssystem – edoobox
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/booking-system-edoobox/js/libraries/moment/moment.min.all.js/wp-content/plugins/booking-system-edoobox/js/dist/admin.js/wp-content/plugins/booking-system-edoobox/css/edoobox-backend.css/wp-content/plugins/booking-system-edoobox/js/libraries/moment/moment.min.all.js/wp-content/plugins/booking-system-edoobox/js/dist/admin.jsbooking-system-edoobox/js/libraries/moment/moment.min.all.js?ver=booking-system-edoobox/js/dist/admin.js?ver=booking-system-edoobox/css/edoobox-backend.css?ver=HTML / DOM Fingerprints
data-edoobox-languageajax_object/wp-json/edoobox[edoobox_booking]