Booking.com Official Search Box Security & Risk Analysis

wordpress.org/plugins/bookingcom-official-searchbox

The official Booking.com search box is a user-friendly, customisable plugin to add the Booking.com search box to your own website in two easy steps.

2K active installs v3.0.6 PHP + WP 3.0+ Updated Mar 12, 2026
accommodationaccommodation-searchboxbooking-com-official-searchboxhotelssearch-hotels
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Booking.com Official Search Box Safe to Use in 2026?

Generally Safe

Score 100/100

Booking.com Official Search Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 22d ago
Risk Assessment

The bookingcom-official-searchbox plugin version 3.0.6 exhibits a generally good security posture based on the static analysis. The plugin demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and implementing nonce checks for its single AJAX entry point. The lack of critical or high-severity taint flows and dangerous function usage further contributes to its positive security profile. The absence of any recorded vulnerabilities, including critical or high-severity ones, in its history suggests a well-maintained and secure codebase over time.

While the overall security is commendable, there are minor areas for improvement. The output escaping, while mostly proper, has a percentage that is not escaped, which could theoretically lead to cross-site scripting (XSS) vulnerabilities if malicious input is ever processed and displayed without proper sanitization. Additionally, the presence of file operations, although only one and without further context, warrants careful consideration to ensure it's implemented securely and doesn't introduce unintended vulnerabilities. The capability checks are also absent, which could be a concern for certain functionalities, though the current entry points appear to be secured by nonces.

In conclusion, bookingcom-official-searchbox v3.0.6 is a secure plugin with a strong foundation. The developers have implemented key security measures effectively. The minor concerns regarding output escaping and file operations are not critical given the overall analysis but should be monitored and addressed for complete security.

Key Concerns

  • 17% of output not properly escaped
  • Presence of file operations
  • No capability checks on entry points
Vulnerabilities
None known

Booking.com Official Search Box Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Booking.com Official Search Box Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
45
213 escaped
Nonce Checks
1
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

83% escaped258 total outputs
Attack Surface

Booking.com Official Search Box Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_bos_previewinc\core-functions.php:580
WordPress Hooks 12
actionrest_api_initbooking-official-searchbox.php:47
actionadmin_menuinc\core-functions.php:22
actionadmin_enqueue_scriptsinc\core-functions.php:32
actionplugins_loadedinc\core-functions.php:37
actionadmin_noticesinc\core-functions.php:54
actionadmin_initinc\core-functions.php:72
actionadd_meta_boxesinc\helpers\meta_boxes.php:12
actionsave_postinc\helpers\meta_boxes.php:93
actionwp_enqueue_scriptsinc\static.php:162
actionadmin_enqueue_scriptsinc\static.php:163
actionwidgets_initinc\widget\bos_widget.php:14
actioninitintegrations\gutenburg\bookingcom-searchbox-block\bookingcom-searchbox-block.php:30
Maintenance & Trust

Booking.com Official Search Box Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 12, 2026
PHP min version
Downloads120K

Community Trust

Rating48/100
Number of ratings8
Active installs2K
Developer Profile

Booking.com Official Search Box Developer Profile

SPBooking.com

2 plugins · 4K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
840 days
View full developer profile
Detection Fingerprints

How We Detect Booking.com Official Search Box

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bookingcom-official-searchbox/assets/css/bos_searchbox.css/wp-content/plugins/bookingcom-official-searchbox/assets/css/bos_settings.css/wp-content/plugins/bookingcom-official-searchbox/assets/css/jquery-ui.css/wp-content/plugins/bookingcom-official-searchbox/assets/css/daterangepicker.css/wp-content/plugins/bookingcom-official-searchbox/assets/css/bos_dynamic.css/wp-content/plugins/bookingcom-official-searchbox/assets/js/bos_main.js/wp-content/plugins/bookingcom-official-searchbox/assets/js/daterangepicker.js/wp-content/plugins/bookingcom-official-searchbox/assets/js/bos_date.js+2 more
Script Paths
wp-content/plugins/bookingcom-official-searchbox/assets/js/bos_main.jswp-content/plugins/bookingcom-official-searchbox/assets/js/daterangepicker.jswp-content/plugins/bookingcom-official-searchbox/assets/js/bos_date.jswp-content/plugins/bookingcom-official-searchbox/assets/js/bos_general.jswp-content/plugins/bookingcom-official-searchbox/assets/js/moment-with-locales.min.js
Version Parameters
bookingcom-official-searchbox/style.css?ver=bookingcom-official-searchbox/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
bos-searchbox-wrapbos-searchbox-input
HTML Comments
Copyright 2014-2022 Partnerships at Booking.com ( email : wp-plugins@booking.com )This program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License+1 more
Data Attributes
data-destination-iddata-widget-type
JS Globals
BOS_PLUGIN_DIR_URLBOS_PLUGIN_MAIN_FILEBOS_PLUGIN_MAIN_PATHBOS_DEFAULT_AIDBOS_DEST_TYPEBOS_FLEXIBLE_DATES+6 more
REST Endpoints
/wp-json/bookingcom-official-searchbox/v1/destinations
Shortcode Output
[bookingcom_search_widget]
FAQ

Frequently Asked Questions about Booking.com Official Search Box