
E-cab Taxi Booking Manager for Woocommerce Security & Risk Analysis
wordpress.org/plugins/ecab-taxi-booking-managerTaxi Booking & Cab Booking for WooCommerce. Chauffeur service with fare calculator, distance pricing, and OpenStreetMap.
Is E-cab Taxi Booking Manager for Woocommerce Safe to Use in 2026?
Generally Safe
Score 86/100E-cab Taxi Booking Manager for Woocommerce has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "ecab-taxi-booking-manager" plugin version 2.0.2 exhibits a concerning security posture, despite some positive indicators. While a significant portion of SQL queries and output operations are properly handled, the presence of 20 unprotected AJAX handlers represents a substantial attack surface that could be exploited by unauthenticated users. The static analysis also flags two instances of the dangerous `unserialize` function, a known vector for deserialization vulnerabilities, and the taint analysis reveals two high-severity flows with unsanitized paths, indicating potential for serious compromise. The plugin's vulnerability history is particularly alarming, with four known CVEs including one critical and one high severity. The fact that the last vulnerability was identified in August 2025 (presumably a typo and meant to be in the past, but still indicating recent past issues) and that the common vulnerability types include missing authorization, deserialization of untrusted data, and XSS, paints a picture of recurring and severe security flaws. While the use of prepared statements and proper output escaping are strengths, the numerous unprotected entry points, dangerous function usage, critical taint flows, and persistent vulnerability history heavily outweigh these positives, suggesting a high-risk plugin requiring immediate attention and remediation.
Key Concerns
- 20 unprotected AJAX handlers
- 2 dangerous functions (unserialize)
- 2 high severity taint flows
- 1 critical unpatched CVE
- 1 high severity unpatched CVE
- 2 medium severity unpatched CVEs
- Common vulnerability types: Deserialization of Untrusted Data
- Common vulnerability types: Missing Authorization
- Common vulnerability types: Cross-site Scripting
E-cab Taxi Booking Manager for Woocommerce Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
E-cab Taxi Booking Manager for Woocommerce <= 2.0.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Taxi Booking Manager for WooCommerce <= 1.3.0 - Missing Authorization
Taxi Booking Manager for Woocommerce | E-cab <= 1.3.0 - Missing Authorization to Unauthenticated Privilege Escalation via Account Takeover
Taxi Booking Manager for WooCommerce <= 1.2.1 - Missing Authorization
Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab <= 1.1.8 - Authenticated (Contributor+) PHP Object Injection
Taxi Booking Manager for WooCommerce – WordPress plugin | Ecab <= 1.0.9 - Authenticated (Admin+) Stored Cross-Site Scripting
E-cab Taxi Booking Manager for Woocommerce Release Timeline
E-cab Taxi Booking Manager for Woocommerce Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
E-cab Taxi Booking Manager for Woocommerce Attack Surface
AJAX Handlers 30
Shortcodes 1
WordPress Hooks 156
Scheduled Events 1
Maintenance & Trust
E-cab Taxi Booking Manager for Woocommerce Maintenance & Trust
Maintenance Signals
Community Trust
E-cab Taxi Booking Manager for Woocommerce Alternatives
Cab Grid
cab-grid
Easily add a taxi fare price calculator to your website via shortcode [cabGrid] or widget. Simply enter journey prices in a table.
Car Rental Manager – Online Vehicle Booking System
car-rental-manager
WPCarRently – ready-to-use WordPress car rental booking plugin. Manage vehicles, WooCommerce payments, and bookings effortlessly for your business.
Cab fare calculator
cab-fare-calculator
This plugin will add an online taxi booking form on your WordPress website. You will be able to manage your vehicles and orders through the back end.
Executive VIP Transfer Service
executive-vip-transfer-service
Complete VIP transfer booking plugin for luxury chauffeur services, airport pickups, and private tours with distance-based pricing.
E-cab Taxi Booking Manager for Woocommerce Developer Profile
11 plugins · 12K total installs
How We Detect E-cab Taxi Booking Manager for Woocommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ecab-taxi-booking-manager/Frontend/css/mptbm-frontend.css/wp-content/plugins/ecab-taxi-booking-manager/Frontend/js/mptbm-frontend.js/wp-content/plugins/ecab-taxi-booking-manager/Frontend/js/gmap.js/wp-content/plugins/ecab-taxi-booking-manager/assets/admin/css/mptbm-admin.css/wp-content/plugins/ecab-taxi-booking-manager/assets/admin/js/mptbm-admin.js/wp-content/plugins/ecab-taxi-booking-manager/assets/admin/js/custom.js/wp-content/plugins/ecab-taxi-booking-manager/Frontend/js/mptbm-frontend.js/wp-content/plugins/ecab-taxi-booking-manager/Frontend/js/gmap.jsecab-taxi-booking-manager/style.css?ver=ecab-taxi-booking-manager/script.js?ver=HTML / DOM Fingerprints
mptbm_booking_formmptbm-date-pickermptbm-time-pickermptbm-vehicle-selectionmptbm-map-container<!-- E-cab Taxi Booking Manager Start --><!-- E-cab Taxi Booking Manager End -->data-mptbm-booking-iddata-mptbm-pricedata-mptbm-locationdata-mptbm-destinationmptbm_frontend_paramsmptbm_map_settings/wp-json/mptbm/v1/booking/wp-json/mptbm/v1/locations[mptbm_booking][mptbm_booking price_based="manual" form="inline"][mptbm_booking price_based="fixed_hourly"][mptbm_booking tab="yes" tabs="hourly,distance,manual"]