Elite Stay Helper – Create Cpts and taxonomy for rooms Security & Risk Analysis

wordpress.org/plugins/elite-stay-helper

The plugin by Kamaldhari Infotech streamlines hotel management, offering custom post types, taxonomy, and meta fields. Easily handle rooms,testimonial …

0 active installs v1.0.2 PHP 8.0+ WP 6.0+ Updated Feb 21, 2025
custom-post-typescustom-taxonomyhotelmeta-fields
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Elite Stay Helper – Create Cpts and taxonomy for rooms Safe to Use in 2026?

Generally Safe

Score 92/100

Elite Stay Helper – Create Cpts and taxonomy for rooms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "elite-stay-helper" v1.0.2 plugin exhibits a strong security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is commendable. Furthermore, the high percentage of properly escaped output and the presence of nonce checks indicate good development practices aimed at preventing common web vulnerabilities. The plugin also has a clean vulnerability history with no recorded CVEs, suggesting a history of secure development or prompt patching by maintainers.

However, a potential area for concern lies in the reliance on shortcodes as the primary entry point, totaling thirteen. While the static analysis indicates zero unprotected entry points, the lack of explicit capability checks on these shortcodes leaves room for potential privilege escalation if not handled internally with robust authorization logic. The presence of only two nonce checks across the entire plugin could also be insufficient if multiple shortcodes handle sensitive operations.

In conclusion, the plugin demonstrates a solid foundation in secure coding practices. The absence of critical issues in taint analysis and the clean vulnerability history are significant strengths. The main areas for vigilance are the potential for authorization bypass within the shortcode handlers and the limited number of explicit capability checks. Overall, the risk is currently assessed as low, but continued monitoring for authorization vulnerabilities within the shortcode functionality is advised.

Key Concerns

  • No explicit capability checks on shortcodes
  • Limited nonce checks
Vulnerabilities
None known

Elite Stay Helper – Create Cpts and taxonomy for rooms Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Elite Stay Helper – Create Cpts and taxonomy for rooms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
177 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

99% escaped179 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<Shortcode_Class> (class\Shortcode_Class.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Elite Stay Helper – Create Cpts and taxonomy for rooms Attack Surface

Entry Points13
Unprotected0

Shortcodes 13

[eshelite_home_booking_form] class\Shortcode_Class.php:212
[eshelite_home_newsletter_form] class\Shortcode_Class.php:213
[eshelite_rooms_preview] class\Shortcode_Class.php:214
[eshelite_hidden_gems] class\Shortcode_Class.php:215
[eshelite_testimonials] class\Shortcode_Class.php:216
[eshelite_blogs_preview] class\Shortcode_Class.php:217
[eshelite_roomspg_room_preview] class\Shortcode_Class.php:218
[eshelite_local_pg_hidden_gems] class\Shortcode_Class.php:219
[eshelite_adventures] class\Shortcode_Class.php:220
[eshelite_offers_display] class\Shortcode_Class.php:221
[eshelite_offers_roompreview] class\Shortcode_Class.php:222
[eshelite_contactus_form] class\Shortcode_Class.php:223
[eshelite_map_shortcode] class\Shortcode_Class.php:224
WordPress Hooks 22
actioninitclass\Shortcode_Class.php:27
actioninitclass\Shortcode_Class.php:28
actionadd_meta_boxesclass\Shortcode_Class.php:29
actionsave_postclass\Shortcode_Class.php:30
actionwp_enqueue_scriptsclass\Shortcode_Class.php:31
actionadmin_enqueue_scriptsclass\Shortcode_Class.php:32
actionpost_edit_form_tagclass\Shortcode_Class.php:33
actionroom_amenities_term_edit_form_tagclass\Shortcode_Class.php:34
actionroom_amenities_term_new_form_tagclass\Shortcode_Class.php:35
actionhotel_amenities_term_edit_form_tagclass\Shortcode_Class.php:36
actionhotel_amenities_term_new_form_tagclass\Shortcode_Class.php:37
actionroom_amenities_add_form_fieldsclass\Shortcode_Class.php:267
actionroom_amenities_edit_form_fieldsclass\Shortcode_Class.php:268
actionhotel_amenities_add_form_fieldsclass\Shortcode_Class.php:269
actionhotel_amenities_edit_form_fieldsclass\Shortcode_Class.php:270
actionedited_room_amenitiesclass\Shortcode_Class.php:271
actioncreated_room_amenitiesclass\Shortcode_Class.php:272
actionedited_hotel_amenitiesclass\Shortcode_Class.php:273
actioncreated_hotel_amenitiesclass\Shortcode_Class.php:274
actioninitelite-stay-helper.php:30
actionadmin_menuelite-stay-helper.php:49
actionadmin_enqueue_scriptselite-stay-helper.php:115
Maintenance & Trust

Elite Stay Helper – Create Cpts and taxonomy for rooms Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 21, 2025
PHP min version8.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Elite Stay Helper – Create Cpts and taxonomy for rooms Developer Profile

KamalDhari Infotech

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Elite Stay Helper – Create Cpts and taxonomy for rooms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/elite-stay-helper/admin/css/style.css/wp-content/plugins/elite-stay-helper/admin/js/hm-admin.js
Script Paths
/wp-content/plugins/elite-stay-helper/assets/js/owl.carousel.min.js/wp-content/plugins/elite-stay-helper/assets/elite_helper_script.js/wp-content/plugins/elite-stay-helper/assets/js/cstm_admin.js
Version Parameters
elite-stay-helper/admin/css/style.css?ver=elite-stay-helper/admin/js/hm-admin.js?ver=elite-stay-helper/assets/css/elite_stay.css?ver=elite-stay-helper/assets/css/elite_stay_responsive.css?ver=elite-stay-helper/assets/js/owl.carousel.min.js?ver=elite-stay-helper/assets/css/owl.carousel.css?ver=elite-stay-helper/assets/elite_helper_script.js?ver=elite-stay-helper/assets/js/cstm_admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
elitestay-demo-import-btnelitestay-import-status
Data Attributes
id="elitestay-demo-import-btn"id="elitestay-import-status"
JS Globals
ajaxurljQuery
FAQ

Frequently Asked Questions about Elite Stay Helper – Create Cpts and taxonomy for rooms