
Twice Commerce – Easy Rental Booking System Security & Risk Analysis
wordpress.org/plugins/embed-rentleFree rental and booking plugin for Wordpress websites by Twice Commerce. Reservations with real-time inventory availability for rentals and activity s …
Is Twice Commerce – Easy Rental Booking System Safe to Use in 2026?
Generally Safe
Score 99/100Twice Commerce – Easy Rental Booking System has a strong security track record. Known vulnerabilities have been patched promptly.
The 'embed-rentle' plugin v1.4 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests, combined with the use of prepared statements for all SQL queries, are strong indicators of secure coding practices. However, there are areas for improvement. The code analysis reveals a lack of explicit nonce and capability checks for its entry points, including shortcodes. While no critical taint flows were identified in the static analysis, the absence of checks on user input before processing it through shortcodes could potentially lead to vulnerabilities if the output escaping is not consistently applied or if future updates introduce new vulnerabilities. The plugin's vulnerability history shows a past medium-severity Cross-Site Scripting (XSS) vulnerability, which, although currently patched, highlights a recurring pattern of input neutralization issues. This suggests that careful review of all input handling, especially for shortcodes, remains important. Overall, the plugin has a solid foundation with good practices in place, but the lack of specific input validation and authorization checks on its entry points, coupled with historical XSS issues, warrant attention to maintain a robust security profile.
Key Concerns
- Lack of nonce checks on entry points
- Lack of capability checks on entry points
- Some output escaping is not proper
- Past medium severity vulnerability (XSS)
Twice Commerce – Easy Rental Booking System Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Twice Commerce <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Twice Commerce – Easy Rental Booking System Code Analysis
Output Escaping
Twice Commerce – Easy Rental Booking System Attack Surface
Shortcodes 2
WordPress Hooks 3
Maintenance & Trust
Twice Commerce – Easy Rental Booking System Maintenance & Trust
Maintenance Signals
Community Trust
Twice Commerce – Easy Rental Booking System Alternatives
Booqable Rental Plugin
booqable-rental-reservations
Booqable - WordPress Rental Plugin
Bukza
bukza
Flexible Online Booking Tools. Reservation System for Services, Rentals and Events.
EZRentOut Online Webstore
ezrentout-online-webstore
EZRentOut enables you to stay on top of your inventory at all times and offer seamless rentals to all your customers. Simplify online renting with our …
WP Booking System – Booking Calendar
wp-booking-system
The booking calendar plugin for WordPress. Get easy online booking with this lightweight and powerful booking calendar.
Pinpoint Booking System – Version 2
booking-system
Book anything, anytime, anywhere.
Twice Commerce – Easy Rental Booking System Developer Profile
1 plugin · 400 total installs
How We Detect Twice Commerce – Easy Rental Booking System
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/embed-rentle/build/index.js/wp-content/plugins/embed-rentle/build/style.csshttps://cdn.rentle.io/embed/bundle.jsHTML / DOM Fingerprints
[rentle_shop][twice_commerce_shop]