
Duitku for VikBooking WordPress Security & Risk Analysis
wordpress.org/plugins/duitku-for-vikDuitku Add-on for VikBooking. Ready to get online booking payment for your rent business?
Is Duitku for VikBooking WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Duitku for VikBooking WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "duitku-for-vik" v1.0.0 plugin exhibits a strong security posture in several key areas, as indicated by the static analysis. Notably, there are no dangerous functions identified, all SQL queries utilize prepared statements, and all output is properly escaped. Furthermore, the absence of any recorded vulnerabilities or CVEs suggests a diligent approach to security development or a lack of past issues. The plugin also demonstrates minimal external dependencies and appears to have a very small attack surface, with no reported AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected.
However, a significant concern arises from the complete lack of nonce checks and capability checks. This indicates a potential weakness, as it means that core WordPress security mechanisms designed to prevent CSRF attacks and ensure proper user permissions are not being utilized for any of the plugin's operations. While the current analysis shows no direct vulnerabilities stemming from this, it represents a missed opportunity to strengthen the plugin's defense against common attack vectors. The presence of file operations and external HTTP requests, while not inherently insecure, warrants careful review to ensure they are implemented safely and without introducing unforeseen risks, especially given the absence of explicit authorization checks.
In conclusion, "duitku-for-vik" v1.0.0 scores well on fundamental secure coding practices like sanitization and data protection within its operations. The clean vulnerability history is a positive indicator. The primary area for improvement and concern lies in the complete omission of nonce and capability checks, which is a critical aspect of WordPress security. Addressing this oversight would significantly enhance the plugin's overall security resilience.
Key Concerns
- Missing nonce checks
- Missing capability checks
Duitku for VikBooking WordPress Security Vulnerabilities
Duitku for VikBooking WordPress Code Analysis
Output Escaping
Duitku for VikBooking WordPress Attack Surface
WordPress Hooks 17
Maintenance & Trust
Duitku for VikBooking WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Duitku for VikBooking WordPress Alternatives
Duitku for GiveWP
duitku-for-givewp
Duitku Add-on for Give
Duitku Payment Gateway
duitku-social-payment-gateway
Do you want the best solution to accept Credit Cards, e-wallet, and Various Bank Transfers on your website? Our Payment Gateway for WooCommerce plugin …
Billingotomatis – Tren Otomatisasi Indonesia
billingotomatis-payment-gateway-indonesia
Billingotomatis merupakan layanan yang bisa membuat bisnis Anda menjadi otomatis, menghemat waktu, dan menambah prestise bisnis Anda.
GiveWP – Donation Plugin and Fundraising Platform
give
Accept donations and begin fundraising with GiveWP, the highest rated WordPress donation plugin for online giving.
Donations via PayPal
paypal-donations
Easy, simple setup to add a PayPal Donation button as a Widget or with a shortcode.
Duitku for VikBooking WordPress Developer Profile
4 plugins · 900 total installs
How We Detect Duitku for VikBooking WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/duitku-for-vik/vikbooking/duitku.pngHTML / DOM Fingerprints
<!-- JPayment -->data-payment-name