CoverManager Security & Risk Analysis

wordpress.org/plugins/covermanager

Booking engine for restaurants.

90 active installs v0.0.1 PHP + WP 3.0.1+ Updated Oct 13, 2017
reservationrestaurants
64
C · Use Caution
CVEs total1
Unpatched1
Last CVEMar 31, 2025
Safety Verdict

Is CoverManager Safe to Use in 2026?

Use With Caution

Score 64/100

CoverManager has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Mar 31, 2025Updated 8yr ago
Risk Assessment

The Covermanager plugin version 0.0.1 exhibits a mixed security posture. While the static analysis reveals a clean codebase with no detected dangerous functions, raw SQL queries, unescaped output, file operations, external requests, or nonce/capability checks, this lack of certain security mechanisms is also a concern. The absence of any detected taint flows and the presence of only one shortcode as an entry point with no apparent authentication checks suggest a limited attack surface in theory. However, the plugin's vulnerability history is a significant red flag. With one known medium severity Cross-Site Scripting (XSS) vulnerability, which is currently unpatched, the plugin poses a tangible risk. The fact that the last vulnerability was so recent (2025-03-31) and remains unpatched is particularly worrying, indicating a lack of timely security updates from the developer.

Key Concerns

  • Unpatched medium severity CVE
  • Missing capability checks on entry points
  • Missing nonce checks on entry points
Vulnerabilities
1

CoverManager Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31620medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CoverManager <= 0.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 31, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

CoverManager Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

CoverManager Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[covermanager] covermanager.php:54
Maintenance & Trust

CoverManager Maintenance & Trust

Maintenance Signals

WordPress version tested3.6.1
Last updatedOct 13, 2017
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

CoverManager Developer Profile

carperfer

1 plugin · 90 total installs

69
trust score
Avg Security Score
64/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect CoverManager

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<iframe title="Reservas" src="https://www.covermanager.com/reservation/module_restaurant/
FAQ

Frequently Asked Questions about CoverManager