
BookingDaddy – Booking & Appointment Made Bold, Easy, and Smart Security & Risk Analysis
wordpress.org/plugins/bookingdaddyBookingDaddy is a WooCommerce booking plugin for salons, clinics, turf rentals, and more. Accept online bookings and appointments!
Is BookingDaddy – Booking & Appointment Made Bold, Easy, and Smart Safe to Use in 2026?
Generally Safe
Score 100/100BookingDaddy – Booking & Appointment Made Bold, Easy, and Smart has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bookingdaddy" v1.0.0 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, with 100% using prepared statements, and a very high percentage (98%) of output being properly escaped, significantly reducing the risk of common cross-site scripting (XSS) vulnerabilities. The absence of known CVEs and vulnerabilities in its history is also a strong indicator of a relatively secure development lifecycle so far. However, the plugin presents a notable concern with its attack surface. It has two AJAX handlers, both of which lack authentication checks. This is a significant security weakness that could allow unauthenticated users to trigger potentially harmful actions within the plugin.
The taint analysis shows no critical or high severity flows with unsanitized paths, which is reassuring. Similarly, the lack of dangerous functions and the presence of nonce checks on some actions are positive signs. Despite the strong internal code hygiene regarding SQL and output, the unprotected AJAX endpoints represent a clear and present risk. The absence of capability checks on these endpoints further exacerbates this issue, meaning any user, even a subscriber or guest, could potentially interact with these handlers. Therefore, while many aspects of the plugin's code are well-secured, the unprotected AJAX endpoints are a critical vulnerability that needs immediate attention.
Key Concerns
- AJAX handlers without authentication checks
- AJAX handlers without capability checks
BookingDaddy – Booking & Appointment Made Bold, Easy, and Smart Security Vulnerabilities
BookingDaddy – Booking & Appointment Made Bold, Easy, and Smart Code Analysis
Output Escaping
Data Flow Analysis
BookingDaddy – Booking & Appointment Made Bold, Easy, and Smart Attack Surface
AJAX Handlers 2
WordPress Hooks 14
Maintenance & Trust
BookingDaddy – Booking & Appointment Made Bold, Easy, and Smart Maintenance & Trust
Maintenance Signals
Community Trust
BookingDaddy – Booking & Appointment Made Bold, Easy, and Smart Alternatives
LatePoint – Calendar Booking Plugin for Appointments and Events
latepoint
Optimize your appointment scheduling with our plugin. Sync calendars, automate reminders, and keep your bookings organized.
SimplyBook.me – Booking and reservations calendar
simplybook
Simply add a booking calendar to your site to schedule bookings, reservations, appointments and to collect payments.
EMC – Easily Embed Calendly Scheduling
embed-calendly-scheduling
Embed Calendly scheduling pages in WordPress and optimize your booking flow with analytics, availability indicator, and conversion tools.
Salon Booking System – Free Version
salon-booking-system
Appointment scheduling plugin for salons, spas, and wellness centers to streamline bookings and improve customer satisfaction.
Easy Appointment Booking & Scheduling System – Webba Booking Calendar
webba-booking-lite
Free Appointment Booking Plugin 📅 Unlimited appointments, booking management, calendar sync, notifications, 5* support = powerful booking system!
BookingDaddy – Booking & Appointment Made Bold, Easy, and Smart Developer Profile
4 plugins · 10 total installs
How We Detect BookingDaddy – Booking & Appointment Made Bold, Easy, and Smart
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bookingdaddy/admin/css/bdcp-deactivation.css/wp-content/plugins/bookingdaddy/admin/js/bdcp-deactivation.js/wp-content/plugins/bookingdaddy/admin/js/bdcp-deactivation.jsbookingdaddy/admin/css/bdcp-deactivation.css?ver=bookingdaddy/admin/js/bdcp-deactivation.js?ver=HTML / DOM Fingerprints
show_if_bdcp_bookable_productdata-target="bdcp_bookable_product_options_product_data"bdcp_deactivation