
Domilocus Security & Risk Analysis
wordpress.org/plugins/domilocusComplete booking and property management solution for vacation rentals, apartments, and accommodations with backend administration.
Is Domilocus Safe to Use in 2026?
Generally Safe
Score 100/100Domilocus has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'domilocus' plugin v1.0.17 exhibits a generally good security posture, with a strong emphasis on secure coding practices. The plugin demonstrates a high percentage of properly escaped outputs and a significant portion of SQL queries utilizing prepared statements. The absence of known CVEs and a clean vulnerability history further contribute to this positive assessment. The static analysis also indicates robust use of nonce and capability checks for its entry points, which are all protected. However, a notable concern arises from the taint analysis, which identified 13 flows with unsanitized paths, including 7 of high severity. This suggests potential vulnerabilities where user-supplied data might be processed without adequate sanitization, leading to risks like path traversal or unintended file operations, despite the limited number of file operations and external HTTP requests. While the plugin avoids common pitfalls like raw SQL or unescaped output, the unsanitized path flows are a significant weakness that requires immediate attention. Overall, the plugin has strong foundations but has a critical area for improvement in data sanitization, which balances its strengths with potential exploitable weaknesses.
Key Concerns
- High severity unsanitized path flows
- Unsanitized path flows identified
- Some SQL queries not using prepared statements
Domilocus Security Vulnerabilities
Domilocus Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Domilocus Attack Surface
AJAX Handlers 22
Shortcodes 6
WordPress Hooks 56
Scheduled Events 1
Maintenance & Trust
Domilocus Maintenance & Trust
Maintenance Signals
Community Trust
Domilocus Alternatives
SimplyBook.me – Booking and reservations calendar
simplybook
Simply add a booking calendar to your site to schedule bookings, reservations, appointments and to collect payments.
FareHarbor for WordPress
fareharbor
Easily add FareHarbor reservation calendars, booking embeds, and buttons to your site.
Pinpoint Booking System – Version 2
booking-system
Book anything, anytime, anywhere.
Salon Booking System – Free Version
salon-booking-system
Appointment scheduling plugin for salons, spas, and wellness centers to streamline bookings and improve customer satisfaction.
SuperSaaS – online appointment scheduling
supersaas-appointment-scheduling
SuperSaaS is a flexible appointment scheduling system that works with many different businesses. The basic version is free.
Domilocus Developer Profile
1 plugin · 0 total installs
How We Detect Domilocus
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/domilocus/assets/css/styles.css/wp-content/plugins/domilocus/assets/js/domilocus-script.js/wp-content/plugins/domilocus/assets/css/customizer.css/wp-content/plugins/domilocus/assets/js/customizer.js/wp-content/plugins/domilocus/assets/js/domilocus-frontend.js/wp-content/plugins/domilocus/assets/js/domilocus-script.js/wp-content/plugins/domilocus/assets/js/customizer.js/wp-content/plugins/domilocus/assets/js/domilocus-frontend.jsdomilocus/assets/css/styles.css?ver=domilocus/assets/js/domilocus-script.js?ver=domilocus/assets/css/customizer.css?ver=domilocus/assets/js/customizer.js?ver=domilocus/assets/js/domilocus-frontend.js?ver=HTML / DOM Fingerprints
domilocus-booking-formdomilocus-calendar-wrapperdomilocus-property-details<!-- Domilocus Booking Form Start --><!-- Domilocus Calendar Start -->data-domilocus-property-iddata-domilocus-booking-idwindow.domilocusConfigvar domilocus_params/wp-json/domilocus/v1/bookings/wp-json/domilocus/v1/properties[domilocus_booking_form][domilocus_calendar][domilocus_property_details]