Duitku for VikBooking WordPress Security & Risk Analysis

wordpress.org/plugins/duitku-for-vik

Duitku Add-on for VikBooking. Ready to get online booking payment for your rent business?

10 active installs v1.0.0 PHP + WP 6.0.1+ Updated Aug 30, 2022
bcadonationduitkuindonesiapaymentgateways
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Duitku for VikBooking WordPress Safe to Use in 2026?

Generally Safe

Score 85/100

Duitku for VikBooking WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "duitku-for-vik" v1.0.0 plugin exhibits a strong security posture in several key areas, as indicated by the static analysis. Notably, there are no dangerous functions identified, all SQL queries utilize prepared statements, and all output is properly escaped. Furthermore, the absence of any recorded vulnerabilities or CVEs suggests a diligent approach to security development or a lack of past issues. The plugin also demonstrates minimal external dependencies and appears to have a very small attack surface, with no reported AJAX handlers, REST API routes, shortcodes, or cron events that are unprotected.

However, a significant concern arises from the complete lack of nonce checks and capability checks. This indicates a potential weakness, as it means that core WordPress security mechanisms designed to prevent CSRF attacks and ensure proper user permissions are not being utilized for any of the plugin's operations. While the current analysis shows no direct vulnerabilities stemming from this, it represents a missed opportunity to strengthen the plugin's defense against common attack vectors. The presence of file operations and external HTTP requests, while not inherently insecure, warrants careful review to ensure they are implemented safely and without introducing unforeseen risks, especially given the absence of explicit authorization checks.

In conclusion, "duitku-for-vik" v1.0.0 scores well on fundamental secure coding practices like sanitization and data protection within its operations. The clean vulnerability history is a positive indicator. The primary area for improvement and concern lies in the complete omission of nonce and capability checks, which is a critical aspect of WordPress security. Addressing this oversight would significantly enhance the plugin's overall security resilience.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Duitku for VikBooking WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Duitku for VikBooking WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
13 escaped
Nonce Checks
0
Capability Checks
0
File Operations
5
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped13 total outputs
Attack Surface

Duitku for VikBooking WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actioninitduitku-for-vik.php:23
filtervikwp_vikupdater_duitku_versionduitku-for-vik.php:33
filtervikwp_vikupdater_duitku_pathduitku-for-vik.php:44
filterget_supported_payments_vikrestaurantsduitku-for-vik.php:60
actionload_payment_gateway_vikrestaurantsduitku-for-vik.php:83
filterget_supported_payments_vikrentitemsduitku-for-vik.php:109
actionload_payment_gateway_vikrentitemsduitku-for-vik.php:132
filterget_supported_payments_vikrentcarduitku-for-vik.php:158
actionload_payment_gateway_vikrentcarduitku-for-vik.php:181
filterget_supported_payments_vikappointmentsduitku-for-vik.php:207
actionload_payment_gateway_vikappointmentsduitku-for-vik.php:230
filterget_supported_payments_vikbookingduitku-for-vik.php:256
actionload_payment_gateway_vikbookingduitku-for-vik.php:279
filtervikbooking_oconfirm_payment_logoduitku-for-vik.php:308
actionpayment_after_begin_transaction_vikbookingvikbooking\duitku.php:16
actionpayment_before_validate_transaction_vikbookingvikbooking\duitku.php:55
actionpayment_on_after_validation_vikbookingvikbooking\duitku.php:117
Maintenance & Trust

Duitku for VikBooking WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedAug 30, 2022
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Duitku for VikBooking WordPress Developer Profile

rayhanduitku

4 plugins · 900 total installs

76
trust score
Avg Security Score
96/100
Avg Patch Time
155 days
View full developer profile
Detection Fingerprints

How We Detect Duitku for VikBooking WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/duitku-for-vik/vikbooking/duitku.png

HTML / DOM Fingerprints

HTML Comments
<!-- JPayment -->
Data Attributes
data-payment-name
FAQ

Frequently Asked Questions about Duitku for VikBooking WordPress