
Cal24h Security & Risk Analysis
wordpress.org/plugins/cal24hEmbed the Cal24h booking experience in WordPress with a shortcode, Gutenberg block, or floating modal.
Is Cal24h Safe to Use in 2026?
Generally Safe
Score 100/100Cal24h has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'cal24h' plugin v1.2.0 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The plugin demonstrates adherence to several security best practices, including the complete absence of dangerous functions and file operations, as well as utilizing prepared statements for all SQL queries. The vast majority of its outputs are properly escaped, and it maintains a low attack surface. The plugin also shows no known CVEs, indicating a history of stability and security.
However, there are a few areas that warrant attention. The plugin makes three external HTTP requests, which, while not inherently a vulnerability, can be a potential vector for issues if the external endpoints are compromised or if the data transmitted is not handled securely. The lack of nonce checks on its single AJAX handler, despite having capability checks, is a notable concern. While capability checks are present, a missing nonce check on an AJAX endpoint can leave it susceptible to Cross-Site Request Forgery (CSRF) attacks if the actions performed are sensitive. The absence of any recorded vulnerabilities historically is a positive sign, but it doesn't negate the need for diligence in addressing potential weaknesses identified in the code analysis.
In conclusion, 'cal24h' v1.2.0 is a relatively secure plugin with a strong foundation in secure coding practices. The main areas for improvement are addressing the potential CSRF risk on the AJAX handler by implementing nonce checks, and careful review of the external HTTP requests to ensure data security. With these minor adjustments, the plugin's security can be further enhanced.
Key Concerns
- Missing nonce check on AJAX handler
Cal24h Security Vulnerabilities
Cal24h Code Analysis
Output Escaping
Data Flow Analysis
Cal24h Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Cal24h Maintenance & Trust
Maintenance Signals
Community Trust
Cal24h Alternatives
LatePoint – Calendar Booking Plugin for Appointments and Events
latepoint
Optimize your appointment scheduling with our plugin. Sync calendars, automate reminders, and keep your bookings organized.
NiftyBukzee – Calendar Booking Plugin for Appointments and Events
niftybukzee
Gain More customers with Quick and Easy 3-step appointment booking with service providers: Calendar, Payments, Google Meet & more.
Events Manager – Calendar, Bookings, Tickets, and more!
events-manager
Events calendar with bookings, scheduling, appointments, event registration, tickets, recurring events, and venue management.
Booking Calendar
booking
Original "Booking Calendar" plugin. Easily manage full-day bookings, time-slot appointments, or events in our all-in-one, outstanding booking system.
SimplyBook.me – Booking and reservations calendar
simplybook
Simply add a booking calendar to your site to schedule bookings, reservations, appointments and to collect payments.
Cal24h Developer Profile
1 plugin · 0 total installs
How We Detect Cal24h
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cal24h/build/style-index.css/wp-content/plugins/cal24h/build/index.js/wp-content/plugins/cal24h/build/index.css/wp-content/plugins/cal24h/build/index.jscal24h/build/style-index.css?ver=cal24h/build/index.js?ver=cal24h/build/index.css?ver=HTML / DOM Fingerprints
cal24h-color-fieldid="cal24h_variant"name="cal24h_options[variant]"id="cal24h_floating_button_label"name="cal24h_options[floating_button_label]"placeholder="Réserver en ligne"id="cal24h_floating_button_color"+10 more/wp-json/cal24h/v1/lookup[cal24h][cal24h mode="event"][cal24h mode="event" event_slug="slug"][cal24h mode="event" org_slug="slug"]