The Webhotelier Integrator Security & Risk Analysis

wordpress.org/plugins/dash-webhotelier-integrator

Plugin to integrate with Webhotelier API

10 active installs v1.0 PHP 5.0+ WP 4.9+ Updated Jan 18, 2019
web-hotelier
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is The Webhotelier Integrator Safe to Use in 2026?

Generally Safe

Score 85/100

The Webhotelier Integrator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "dash-webhotelier-integrator" v1.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any known vulnerabilities in its history is a significant positive indicator. Furthermore, the code demonstrates good practices by using prepared statements for all SQL queries and implementing capability checks. The limited attack surface with no unprotected AJAX handlers or REST API routes also contributes to its security.

However, there are areas that warrant attention. The low percentage of properly escaped output (64%) suggests a moderate risk of Cross-Site Scripting (XSS) vulnerabilities, especially with 116 total outputs analyzed. While the taint analysis did not reveal critical or high-severity flows, it did identify two flows with unsanitized paths. This, combined with the lack of nonce checks, raises concerns about potential Cross-Site Request Forgery (CSRF) or other injection-based attacks if these unsanitized paths are not adequately protected by other means (e.g., within file operations or external requests). The single file operation and single external HTTP request are also potential entry points if not handled with extreme care.

In conclusion, while the plugin has a solid foundation with no known vulnerabilities and good practices in SQL handling, the significant number of unescaped outputs and the presence of unsanitized paths in taint flows present potential weaknesses. These areas should be thoroughly reviewed and mitigated to further enhance the plugin's security.

Key Concerns

  • Low percentage of properly escaped output
  • Unsanitized paths in taint flows
  • No nonce checks
Vulnerabilities
None known

The Webhotelier Integrator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

The Webhotelier Integrator Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

The Webhotelier Integrator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
42
74 escaped
Nonce Checks
0
Capability Checks
2
File Operations
1
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

64% escaped116 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
settingsPage (HalimWebhotelier_OptionsManager.php:294)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

The Webhotelier Integrator Attack Surface

Entry Points3
Unprotected0

Shortcodes 3

[display_searchengine] HalimWebhotelier_Plugin.php:294
[display_promotion] HalimWebhotelier_Plugin.php:295
[booknow] HalimWebhotelier_Plugin.php:297
WordPress Hooks 7
actionadmin_initHalimWebhotelier_OptionsManager.php:270
actionadmin_menuHalimWebhotelier_Plugin.php:290
filterbody_classHalimWebhotelier_Plugin.php:298
actionwp_footerHalimWebhotelier_ShortCodeScriptLoader.php:22
actionadmin_noticeshalim-webhotelier.php:52
actionplugins_loadedihalim-webhotelier.php:77
actionadmin_enqueue_scriptshalim-webhotelier.php:79
Maintenance & Trust

The Webhotelier Integrator Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedJan 18, 2019
PHP min version5.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Alternatives

The Webhotelier Integrator Alternatives

No alternatives data available yet.

Developer Profile

The Webhotelier Integrator Developer Profile

webcreativemaster

4 plugins · 30 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect The Webhotelier Integrator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dash-webhotelier-integrator/js/grabmix-script.js
Script Paths
js/grabmix-script.js

HTML / DOM Fingerprints

CSS Classes
webhotelier-integrator-plugindash-webhotelier-integrator-plugin
Data Attributes
data-site-iddata-engine-colordata-engine-bgcolordata-engine-txtcolordata-api-userdata-api-pw+6 more
JS Globals
window.WebHotelier
Shortcode Output
[webhotelier_integrator][webhotelier_booking_engine][webhotelier_promotions]
FAQ

Frequently Asked Questions about The Webhotelier Integrator