CITS Bridal Live Appointment Security & Risk Analysis

wordpress.org/plugins/bridal-live-appointment

BridalLive Software's default iframe booking system has limitations, which led us to develop a custom form system using the BridalLive API.

0 active installs v1.1.2 PHP 7.0+ WP 5.0+ Updated May 1, 2024
book-appointmentbridal-livebridal-shopbridalliveshop-software
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is CITS Bridal Live Appointment Safe to Use in 2026?

Generally Safe

Score 85/100

CITS Bridal Live Appointment has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "bridal-live-appointment" plugin v1.1.2 exhibits a mixed security posture. On the positive side, it demonstrates excellent practices regarding output escaping, with 100% of outputs being properly handled. Furthermore, 91% of its SQL queries utilize prepared statements, significantly reducing the risk of SQL injection. The plugin also shows no history of known vulnerabilities, suggesting a degree of historical stability and developer diligence. However, significant security concerns arise from its attack surface. Four AJAX handlers are present, and critically, two of these lack any authentication checks, opening a direct pathway for unauthenticated attackers to interact with potentially sensitive functionalities. While no critical or high severity taint flows were identified, the presence of one flow with an unsanitized path warrants further investigation. The absence of capability checks on any entry points is also a notable weakness, as it means that even low-privileged users could potentially trigger actions they should not have access to. The plugin's vulnerability history is clean, but this does not negate the immediate risks presented by the identified code analysis issues.

Key Concerns

  • AJAX handlers without authentication
  • Entry points without capability checks
  • Flows with unsanitized paths
Vulnerabilities
None known

CITS Bridal Live Appointment Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

CITS Bridal Live Appointment Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

CITS Bridal Live Appointment Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
10 prepared
Unescaped Output
0
191 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
4
Bundled Libraries
0

SQL Query Safety

91% prepared11 total queries

Output Escaping

100% escaped191 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
bridal_live__times (public\partials\bridal-live-appointment-public-display.php:77)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

CITS Bridal Live Appointment Attack Surface

Entry Points5
Unprotected2

AJAX Handlers 4

authwp_ajax_bridal_live__timespublic\partials\bridal-live-appointment-public-display.php:75
noprivwp_ajax_bridal_live__timespublic\partials\bridal-live-appointment-public-display.php:76
authwp_ajax_bridal_live__appointmentpublic\partials\bridal-live-appointment-public-display.php:101
noprivwp_ajax_bridal_live__appointmentpublic\partials\bridal-live-appointment-public-display.php:102

Shortcodes 1

[bridal__live__appointment] public\partials\bridal-live-appointment-public-display.php:165
WordPress Hooks 6
actionplugins_loadedincludes\class-bridal-live-appointment.php:111
actionadmin_enqueue_scriptsincludes\class-bridal-live-appointment.php:126
actionadmin_enqueue_scriptsincludes\class-bridal-live-appointment.php:127
actionadmin_menuincludes\class-bridal-live-appointment.php:129
actionwp_enqueue_scriptsincludes\class-bridal-live-appointment.php:144
actionwp_enqueue_scriptsincludes\class-bridal-live-appointment.php:145
Maintenance & Trust

CITS Bridal Live Appointment Maintenance & Trust

Maintenance Signals

WordPress version tested6.5.8
Last updatedMay 1, 2024
PHP min version7.0
Downloads863

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

CITS Bridal Live Appointment Developer Profile

Ashikur Rahman

3 plugins · 0 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CITS Bridal Live Appointment

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bridal-live-appointment/admin/css/bridal-live-appointment-admin.css/wp-content/plugins/bridal-live-appointment/admin/css/owl.carousel.min.css/wp-content/plugins/bridal-live-appointment/admin/css/owl.theme.default.min.css/wp-content/plugins/bridal-live-appointment/admin/js/bridal-live-appointment-admin.js/wp-content/plugins/bridal-live-appointment/admin/js/owl.carousel.min.js
Script Paths
admin/js/bridal-live-appointment-admin.jsadmin/js/owl.carousel.min.js
Version Parameters
bridal-live-appointment-admin.css?ver=owl.carousel.min.css?ver=owl.theme.default.min.css?ver=bridal-live-appointment-admin.js?ver=owl.carousel.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
bridal-live-appointment-deshbordbridal-live-configurationbridal_live_settings
Data Attributes
id="bridal-live-appointment"
FAQ

Frequently Asked Questions about CITS Bridal Live Appointment