Bookster Extra Options Security & Risk Analysis

wordpress.org/plugins/bookster-extra-options

This Extra Options Addon for Bookster allows you to add extra services to your booking forms to collect additional payments from customers.

10 active installs v3.0.0 PHP 7.4+ WP 6.2+ Updated Mar 9, 2026
custom-fieldsextrasoptionsserviceservices
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bookster Extra Options Safe to Use in 2026?

Generally Safe

Score 100/100

Bookster Extra Options has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 25d ago
Risk Assessment

The "bookster-extra-options" v3.0.0 plugin exhibits a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and properly escaped output are significant strengths. Furthermore, the plugin demonstrates a good understanding of WordPress security by implementing capability checks where appropriate. The lack of external HTTP requests and file operations further reduces the potential attack surface.

While the static analysis reveals no immediate critical vulnerabilities, the absence of nonce checks and a complete lack of identified taint flows are areas for attention. A zero taint flow analysis could indicate a very small or non-existent taintable code path, but it could also mean the analysis was incomplete or the code simply didn't trigger the taint analysis engine. The vulnerability history being clear of any known CVEs is a positive sign, suggesting a well-maintained codebase or a plugin that has historically been secure. However, this does not guarantee future security.

In conclusion, the plugin appears to be well-developed from a security perspective, adhering to many best practices. The primary concerns are the lack of explicit nonce checks, which is a standard security measure for many entry points, and the zero taint analysis results, which warrant a closer look to ensure thoroughness. Despite these minor points, the overall security outlook for this version is positive.

Key Concerns

  • Missing nonce checks
Vulnerabilities
None known

Bookster Extra Options Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Bookster Extra Options Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
6 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped6 total outputs
Attack Surface

Bookster Extra Options Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actioninitbookster-extra-options.php:36
actionplugins_loadedbookster-extra-options.php:64
actionadmin_noticesbookster-extra-options.php:72
actionadmin_noticesbookster-extra-options.php:88
actionadmin_noticesbookster-extra-options.php:111
actionwpmu_new_blogsrc\Engine\ActDeact.php:12
actionbookster_after_enqueue_scriptsrc\Engine\Enqueue.php:29
actionbookster_after_enqueue_scriptsrc\Engine\Enqueue.php:30
actioninitsrc\Engine\Enqueue.php:35
filterpre_load_script_translationssrc\Engine\Enqueue.php:36
filterbookster_scripts_dependenciessrc\Engine\Enqueue.php:38
actionbookster_after_enqueue_scriptsrc\Engine\Enqueue.php:39
filterbookster_booking_subquery_json_argssrc\Engine\ExtendBookingModel.php:22
filterbookster_booking_info_query_buildersrc\Engine\ExtendBookingModel.php:23
filterbookster_booking_payload_allowed_keyssrc\Engine\ExtraBookingRequestLogic.php:29
filterbookster_booking_durationsrc\Engine\ExtraBookingRequestLogic.php:30
filterbookster_make_booking_detailssrc\Engine\ExtraBookingRequestLogic.php:31
actionbookster_update_customize_settingssrc\Engine\ExtrasOptions.php:18
actionrest_api_initsrc\Engine\RestAPI.php:14
filterbookster_addon_infossrc\Initialize.php:20
Maintenance & Trust

Bookster Extra Options Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 9, 2026
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Bookster Extra Options Developer Profile

Bookster

6 plugins · 230 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
19 days
View full developer profile
Detection Fingerprints

How We Detect Bookster Extra Options

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bookster-extra-options/assets/dist/extra-options/style.css/wp-content/plugins/bookster-extra-options/assets/dist/extra-options/frontend.js/wp-content/plugins/bookster-extra-options/assets/dist/extra-options/admin.js
Version Parameters
bookster-extra-options/assets/dist/extra-options/style.css?ver=bookster-extra-options/assets/dist/extra-options/frontend.js?ver=bookster-extra-options/assets/dist/extra-options/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
bookster-extra-options
Data Attributes
data-bookster-extra-options
JS Globals
window.bookster_extra_options_params
FAQ

Frequently Asked Questions about Bookster Extra Options