
Bookkeeping Security & Risk Analysis
wordpress.org/plugins/bookkeepingA simple personal financial bookkeeping system.
Is Bookkeeping Safe to Use in 2026?
Generally Safe
Score 85/100Bookkeeping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "bookkeeping" plugin v0.5.3 presents a mixed security posture. On the positive side, it demonstrates good practices by not using dangerous functions, employing prepared statements for all SQL queries, and having no recorded vulnerability history. The attack surface is also zero, meaning there are no direct entry points like AJAX handlers, REST API routes, or shortcodes exposed without authentication or permission checks. Furthermore, no external HTTP requests or file operations are performed, and no bundled libraries are used, reducing potential attack vectors.
However, a significant concern arises from the output escaping. With 100% of outputs not properly escaped, this plugin is highly susceptible to Cross-Site Scripting (XSS) vulnerabilities. Even though the taint analysis shows no critical or high-severity unsanitized paths, the lack of output escaping means that any data displayed to users could potentially be manipulated to execute malicious scripts. The absence of nonce and capability checks, while less critical given the zero attack surface, means that if an entry point were ever introduced without proper checks, it would be a direct vulnerability.
In conclusion, while the plugin benefits from a clean vulnerability history and a lack of direct attack vectors, the pervasive issue of unescaped output is a major security weakness. This needs immediate attention to prevent XSS attacks. The absence of nonce and capability checks, while currently mitigated by the zero attack surface, represents a potential future risk if the plugin evolves.
Key Concerns
- 0% of outputs properly escaped
- No nonce checks
- No capability checks
Bookkeeping Security Vulnerabilities
Bookkeeping Release Timeline
Bookkeeping Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Bookkeeping Attack Surface
WordPress Hooks 2
Maintenance & Trust
Bookkeeping Maintenance & Trust
Maintenance Signals
Community Trust
Bookkeeping Alternatives
Akaunting for WooCommerce
akaunting-for-woocommerce
Akaunting is a free, open source and online accounting software for small businesses and freelancers.
Ocean Custom Sidebar
ocean-custom-sidebar
Generates an unlimited number of sidebars and place them on any page you wish. Go to Theme Panel > Sidebars to create your custom sidebars.
Website Article Monetization By MageNet
website-article-monetization-by-magenet
Get additional income from your website or blog by placing text ads automatically.
Website Monetization by MageNet
website-monetization-by-magenet
Get additional income from your website or blog by placing text ads automatically.
If-So Dynamic Content Personalization
if-so
Personalize any content! Add or replace content according to the visitor's profile and interaction with the site. No coding required!
Bookkeeping Developer Profile
5 plugins · 200 total installs
How We Detect Bookkeeping
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bookkeeping/style.cssbookkeeping/style.css?ver=HTML / DOM Fingerprints
bookkeeping-journalbookkeeping-journal-navdata-type="text"