
Multipurpose Ticket Booking Manager (Bus/Train/Ferry/Boat/Shuttle) Security & Risk Analysis
wordpress.org/plugins/bus-booking-managerThe Multipurpose Ticket Booking Manager is a reliable plugin to book tickets for transportation, such as buses, trains, and ferries in one place.
Is Multipurpose Ticket Booking Manager (Bus/Train/Ferry/Boat/Shuttle) Safe to Use in 2026?
Generally Safe
Score 99/100Multipurpose Ticket Booking Manager (Bus/Train/Ferry/Boat/Shuttle) has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'bus-booking-manager' plugin version 5.0.1 exhibits a generally strong security posture, with most entry points protected by authentication checks and a high percentage of SQL queries utilizing prepared statements and output escaping. The absence of unprotected AJAX handlers, REST API routes, and file operations is commendable. However, the presence of the 'unserialize' function poses a potential risk, as it can be a vector for remote code execution if user-supplied data is unserialized without proper validation and sanitization. While the plugin has a history of one medium-severity Cross-Site Scripting (XSS) vulnerability, it is currently patched, indicating the developers address security issues. The taint analysis shows no critical or high-severity unsanitized paths, which is positive. The plugin's overall security is good, but the 'unserialize' function warrants careful monitoring and potentially further review.
Key Concerns
- Presence of 'unserialize' function
- One medium CVE in history
Multipurpose Ticket Booking Manager (Bus/Train/Ferry/Boat/Shuttle) Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Multipurpose Ticket Booking Manager <= 4.2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Multipurpose Ticket Booking Manager (Bus/Train/Ferry/Boat/Shuttle) Release Timeline
Multipurpose Ticket Booking Manager (Bus/Train/Ferry/Boat/Shuttle) Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Multipurpose Ticket Booking Manager (Bus/Train/Ferry/Boat/Shuttle) Attack Surface
AJAX Handlers 11
Shortcodes 4
WordPress Hooks 97
Maintenance & Trust
Multipurpose Ticket Booking Manager (Bus/Train/Ferry/Boat/Shuttle) Maintenance & Trust
Maintenance Signals
Community Trust
Multipurpose Ticket Booking Manager (Bus/Train/Ferry/Boat/Shuttle) Alternatives
Multipurpose Ticket Booking Manager (Bus/Train/Ferry/Boat/Shuttle) Developer Profile
11 plugins · 12K total installs
How We Detect Multipurpose Ticket Booking Manager (Bus/Train/Ferry/Boat/Shuttle)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/bus-booking-manager/inc/css/wbbm-admin.css/wp-content/plugins/bus-booking-manager/inc/css/wbbm-style.css/wp-content/plugins/bus-booking-manager/inc/js/wbbm-admin.js/wp-content/plugins/bus-booking-manager/inc/js/wbbm-frontend.js/wp-content/plugins/bus-booking-manager/inc/js/wbbm-frontend-script.js/wp-content/plugins/bus-booking-manager/inc/js/wbbm-admin.js/wp-content/plugins/bus-booking-manager/inc/js/wbbm-frontend.js/wp-content/plugins/bus-booking-manager/inc/js/wbbm-frontend-script.jsbus-booking-manager/inc/css/wbbm-admin.css?ver=bus-booking-manager/inc/css/wbbm-style.css?ver=bus-booking-manager/inc/js/wbbm-admin.js?ver=bus-booking-manager/inc/js/wbbm-frontend.js?ver=bus-booking-manager/inc/js/wbbm-frontend-script.js?ver=HTML / DOM Fingerprints
wbbm-admin-sectionwbbm-field-wrapwbbm-date-pickerwbbm-time-pickerwbbm-booking-formwbbm-bus-selection<!-- Added by Sumon --><!-- Language Load --><!-- Added by sumon --><!---------------- -->data-wbbm-actionwbbm_frontend_objWBBM_ADMIN_OBJ/wp-json/bus-booking-manager/v1/get_cities[wbbm_booking_form][wbbm_booking_list][wbbm_search_form]