
Bookwize Integrated Cinnamon Security & Risk Analysis
wordpress.org/plugins/bookwize-integrated-cinnamonIntegrate Bookwize Hotel Booking Engine in your WordPress website and let visitors check availability and rates and make a booking directly from your …
Is Bookwize Integrated Cinnamon Safe to Use in 2026?
Generally Safe
Score 85/100Bookwize Integrated Cinnamon has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'bookwize-integrated-cinnamon' v2.5 plugin exhibits a mixed security posture. While the absence of known CVEs and critical taint flows is positive, several concerning practices were identified in the static analysis. The presence of two AJAX handlers without authentication checks represents a significant attack vector, as these entry points could be exploited by unauthenticated users. Furthermore, the plugin utilizes raw SQL queries without prepared statements, which is a common source of SQL injection vulnerabilities. The low percentage of properly escaped output (11%) also indicates a high risk of cross-site scripting (XSS) vulnerabilities, as user-supplied data might be directly rendered without adequate sanitization.
Despite these critical areas for improvement, the plugin does implement some basic security measures, as evidenced by the presence of nonce and capability checks in a few instances. The lack of external HTTP requests and file operations without clear context also mitigates some potential risks. The vulnerability history being clean is a good sign, suggesting either diligent development or a lack of targeted discovery. However, the identified code-level weaknesses mean that the plugin is vulnerable even without past reported issues. In conclusion, while the plugin has a clean history, the identified static analysis issues, particularly the unprotected AJAX handlers and lack of prepared statements for SQL queries, present a substantial risk that requires immediate attention.
Key Concerns
- AJAX handlers without auth checks
- Raw SQL queries without prepared statements
- Low percentage of properly escaped output
- One instance of missing nonce check for AJAX
Bookwize Integrated Cinnamon Security Vulnerabilities
Bookwize Integrated Cinnamon Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Bookwize Integrated Cinnamon Attack Surface
AJAX Handlers 2
Shortcodes 4
WordPress Hooks 28
Maintenance & Trust
Bookwize Integrated Cinnamon Maintenance & Trust
Maintenance Signals
Community Trust
Bookwize Integrated Cinnamon Alternatives
Sirvoy Booking Engine
sirvoy-booking-engine
Sirvoy booking engine - Non-Commission Direct Bookings from Your Website. Sirvoy can also help you to receive bookings from channels, and much more.
Astro Booking Engine
astro-booking-engine
Use shortcode [astro-booking-engine] to display the booking form. Configure with 5Stelle, Iperbooking, Passepartout, Simple booking, or Vertical booki …
Softinn Hotel Booking Engine
softinn-booking-engine
Unlock room booking power on your WP site with Softinn Hotel Booking Engine, tailored for boutique hotels in Southeast Asia.
MotoPress Hotel Booking
motopress-hotel-booking-lite
The #1 Hotel Booking and Vacation Rental Plugin for WordPress. Online payments, seasons, rates, free or paid extras, coupons, taxes & fees.
MotoPress Hotel Booking for Elementor
mphb-elementor
Build your property rental website visually with MotoPress Hotel Booking plugin shortcodes and Elementor.
Bookwize Integrated Cinnamon Developer Profile
1 plugin · 10 total installs
How We Detect Bookwize Integrated Cinnamon
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bookwize-integrated-cinnamon/css/bookwize-integrated-cinnamon-admin.css/wp-content/plugins/bookwize-integrated-cinnamon/js/bookwize-integrated-cinnamon-admin.jsbookwize-integrated-cinnamon-admin.css?ver=bookwize-integrated-cinnamon-admin.js?ver=HTML / DOM Fingerprints
bookwize_integrated_page_typebw