Car Rental Booking Engine by Ionoleggioauto.com Security & Risk Analysis

wordpress.org/plugins/car-rental-booking-engine-by-ionoleggioauto-com

Adds a car rental search box to your blog so visitors can check availability and compare prices of over 750 car hire companies worldwide.

10 active installs v3.1 PHP + WP + Updated Unknown
alquiler-de-cochescar-hirecar-rentallocation-de-voituresmietwagen
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Car Rental Booking Engine by Ionoleggioauto.com Safe to Use in 2026?

Generally Safe

Score 100/100

Car Rental Booking Engine by Ionoleggioauto.com has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

This plugin exhibits a mixed security posture. On the positive side, it has a very small attack surface with only one entry point (a shortcode) and no observed AJAX handlers or REST API routes. Furthermore, all SQL queries are performed using prepared statements, and there are no recorded vulnerabilities or CVEs, indicating a potentially stable and well-maintained codebase. However, several concerning findings emerge from the static analysis. The presence of `create_function`, a deprecated and often insecure PHP function, is a significant red flag. The extremely low percentage of properly escaped output (4%) suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data is likely being rendered directly without proper sanitization. The lack of nonce checks and capability checks, especially in conjunction with the file operation and the presence of `create_function`, raises concerns about potential unauthorized actions or code execution if an attacker can control any part of the shortcode's execution flow. While there's no history of vulnerabilities, the current static analysis reveals potential weaknesses that could be exploited.

Key Concerns

  • Use of create_function()
  • Low percentage of properly escaped output
  • Lack of nonce checks
  • Lack of capability checks
  • Presence of file operations without auth checks
Vulnerabilities
None known

Car Rental Booking Engine by Ionoleggioauto.com Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Car Rental Booking Engine by Ionoleggioauto.com Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
23
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action('widgets_init', create_function('', 'return register_widget("chh_plugin_widget");'));car-rental-booking-engine-ionoleggioauto.php:196

Output Escaping

4% escaped24 total outputs
Attack Surface

Car Rental Booking Engine by Ionoleggioauto.com Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[car_hire_ionoleggioauto] car-rental-booking-engine-ionoleggioauto.php:774
WordPress Hooks 6
actionplugins_loadedcar-rental-booking-engine-ionoleggioauto.php:56
actionwidgets_initcar-rental-booking-engine-ionoleggioauto.php:196
actionadmin_menucar-rental-booking-engine-ionoleggioauto.php:256
actionadmin_initcar-rental-booking-engine-ionoleggioauto.php:314
actionwp_print_scriptscar-rental-booking-engine-ionoleggioauto.php:1206
actionadmin_noticescar-rental-booking-engine-ionoleggioauto.php:1379
Maintenance & Trust

Car Rental Booking Engine by Ionoleggioauto.com Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedUnknown
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

Car Rental Booking Engine by Ionoleggioauto.com Developer Profile

andreaguerra80

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Car Rental Booking Engine by Ionoleggioauto.com

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/car-rental-booking-engine-by-ionoleggioauto-com/css/custom-css.css/wp-content/plugins/car-rental-booking-engine-by-ionoleggioauto-com/css/style.css/wp-content/plugins/car-rental-booking-engine-by-ionoleggioauto-com/css/responsive.css/wp-content/plugins/car-rental-booking-engine-by-ionoleggioauto-com/js/jquery.car-rental-booking.js/wp-content/plugins/car-rental-booking-engine-by-ionoleggioauto-com/js/custom.js
Script Paths
/wp-content/plugins/car-rental-booking-engine-by-ionoleggioauto-com/js/jquery.car-rental-booking.js/wp-content/plugins/car-rental-booking-engine-by-ionoleggioauto-com/js/custom.js
Version Parameters
car-rental-booking-engine-by-ionoleggioauto-com/css/custom-css.css?ver=car-rental-booking-engine-by-ionoleggioauto-com/css/style.css?ver=car-rental-booking-engine-by-ionoleggioauto-com/css/responsive.css?ver=car-rental-booking-engine-by-ionoleggioauto-com/js/jquery.car-rental-booking.js?ver=car-rental-booking-engine-by-ionoleggioauto-com/js/custom.js?ver=

HTML / DOM Fingerprints

CSS Classes
car-rental-booking-enginecar-rental-widget
HTML Comments
Copyright 2018 Ionoleggioauto.comThis program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License+14 more
Data Attributes
data-car-rental-engine
JS Globals
carRentalBookingEngine
Shortcode Output
[car_rental_booking_engine]
FAQ

Frequently Asked Questions about Car Rental Booking Engine by Ionoleggioauto.com