Bookster PayPal Addon Security & Risk Analysis

wordpress.org/plugins/bookster-paypal

Accept PayPal online payments at Bookster checkout

10 active installs v3.0.0 PHP 7.4+ WP 6.2+ Updated Mar 9, 2026
appointmentscheckoutonline-paymentspaymentspaypal
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Bookster PayPal Addon Safe to Use in 2026?

Generally Safe

Score 100/100

Bookster PayPal Addon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 25d ago
Risk Assessment

The "bookster-paypal" v3.0.0 plugin exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, critical or high-severity taint flows, and the consistent use of prepared statements for SQL queries are all positive indicators. Furthermore, all output appears to be properly escaped, and the plugin does not perform direct file operations, reducing common attack vectors. The limited attack surface with no unprotected entry points is also a significant strength.

However, there are a few areas that warrant attention. The plugin makes 5 external HTTP requests, and without further analysis, it's impossible to ascertain if these are being handled securely, especially concerning potential data leakage or injection vulnerabilities through these requests. Crucially, the complete absence of nonce checks is a significant concern. While there are no unprotected AJAX handlers or REST API routes, the reliance on capability checks alone for the single identified check may not be sufficient to prevent CSRF attacks if any administrative actions are performed without nonces.

In conclusion, the plugin demonstrates good practices in critical areas like SQL and output handling, and its historical security record is clean. The primary weaknesses lie in the external HTTP requests and the lack of nonce checks, which, while not directly exploited in the provided data, represent potential avenues for attack that could be mitigated. The plugin is likely secure against common vulnerabilities based on this snapshot, but further investigation into the external requests and the implementation of nonce checks would enhance its security.

Key Concerns

  • No nonce checks present
  • External HTTP requests made
Vulnerabilities
None known

Bookster PayPal Addon Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Bookster PayPal Addon Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
15 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
5
Bundled Libraries
0

Output Escaping

100% escaped15 total outputs
Attack Surface

Bookster PayPal Addon Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 19
actioninitbookster-paypal.php:36
actionplugins_loadedbookster-paypal.php:64
actionadmin_noticesbookster-paypal.php:72
actionadmin_noticesbookster-paypal.php:88
actionadmin_noticesbookster-paypal.php:111
actionwpmu_new_blogsrc\Engine\ActDeact.php:12
actioninitsrc\Engine\Enqueue.php:30
filterpre_load_script_translationssrc\Engine\Enqueue.php:31
filterbookster_scripts_dependenciessrc\Engine\Enqueue.php:33
actionbookster_after_enqueue_scriptsrc\Engine\Enqueue.php:34
filterbookster_prepare_booking_inputsrc\Engine\PaypalPayment.php:38
filterbookster_validate_booking_inputsrc\Engine\PaypalPayment.php:39
filterbookster_create_booking_transactionsrc\Engine\PaypalPayment.php:41
filterbookster_public_datasrc\Engine\PaypalSettings.php:22
filterbookster_public_datasrc\Engine\PaypalSettings.php:23
filterbookster_manager_datasrc\Engine\PaypalSettings.php:25
actionbookster_update_payment_settingssrc\Engine\PaypalSettings.php:26
actionrest_api_initsrc\Engine\RestAPI.php:14
filterbookster_addon_infossrc\Initialize.php:20
Maintenance & Trust

Bookster PayPal Addon Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 9, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Bookster PayPal Addon Developer Profile

Bookster

6 plugins · 230 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
19 days
View full developer profile
Detection Fingerprints

How We Detect Bookster PayPal Addon

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bookster-paypal/assets/dist/paypal/style.css/wp-content/plugins/bookster-paypal/assets/dist/paypal/frontend.js/wp-content/plugins/bookster-paypal/assets/dist/paypal/admin.js
Script Paths
/wp-content/plugins/bookster-paypal/assets/dist/paypal/frontend.js/wp-content/plugins/bookster-paypal/assets/dist/paypal/admin.js
Version Parameters
bookster-paypal/assets/dist/paypal/style.css?ver=bookster-paypal/assets/dist/paypal/frontend.js?ver=bookster-paypal/assets/dist/paypal/admin.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Bookster PayPal Addon