Twice Commerce – Easy Rental Booking System Security & Risk Analysis

wordpress.org/plugins/embed-rentle

Free rental and booking plugin for Wordpress websites by Twice Commerce. Reservations with real-time inventory availability for rentals and activity s …

400 active installs v1.4 PHP 5.6+ WP 6.7+ Updated Dec 17, 2025
availabilitybookingcalendarrentalreservation
99
A · Safe
CVEs total1
Unpatched0
Last CVEMar 31, 2025
Safety Verdict

Is Twice Commerce – Easy Rental Booking System Safe to Use in 2026?

Generally Safe

Score 99/100

Twice Commerce – Easy Rental Booking System has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Mar 31, 2025Updated 3mo ago
Risk Assessment

The 'embed-rentle' plugin v1.4 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests, combined with the use of prepared statements for all SQL queries, are strong indicators of secure coding practices. However, there are areas for improvement. The code analysis reveals a lack of explicit nonce and capability checks for its entry points, including shortcodes. While no critical taint flows were identified in the static analysis, the absence of checks on user input before processing it through shortcodes could potentially lead to vulnerabilities if the output escaping is not consistently applied or if future updates introduce new vulnerabilities. The plugin's vulnerability history shows a past medium-severity Cross-Site Scripting (XSS) vulnerability, which, although currently patched, highlights a recurring pattern of input neutralization issues. This suggests that careful review of all input handling, especially for shortcodes, remains important. Overall, the plugin has a solid foundation with good practices in place, but the lack of specific input validation and authorization checks on its entry points, coupled with historical XSS issues, warrant attention to maintain a robust security profile.

Key Concerns

  • Lack of nonce checks on entry points
  • Lack of capability checks on entry points
  • Some output escaping is not proper
  • Past medium severity vulnerability (XSS)
Vulnerabilities
1

Twice Commerce – Easy Rental Booking System Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-31543medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Twice Commerce <= 1.3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting

Mar 31, 2025 Patched in 1.3.2 (47d)
Code Analysis
Analyzed Mar 16, 2026

Twice Commerce – Easy Rental Booking System Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
16 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

84% escaped19 total outputs
Attack Surface

Twice Commerce – Easy Rental Booking System Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[rentle_shop] init.php:25
[twice_commerce_shop] init.php:26
WordPress Hooks 3
actioninitinit.php:17
actionwp_headinit.php:18
actioninitplugin.php:58
Maintenance & Trust

Twice Commerce – Easy Rental Booking System Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 17, 2025
PHP min version5.6
Downloads15K

Community Trust

Rating100/100
Number of ratings2
Active installs400
Developer Profile

Twice Commerce – Easy Rental Booking System Developer Profile

Twice Commerce

1 plugin · 400 total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
47 days
View full developer profile
Detection Fingerprints

How We Detect Twice Commerce – Easy Rental Booking System

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/embed-rentle/build/index.js/wp-content/plugins/embed-rentle/build/style.css
Script Paths
https://cdn.rentle.io/embed/bundle.js

HTML / DOM Fingerprints

Shortcode Output
[rentle_shop][twice_commerce_shop]
FAQ

Frequently Asked Questions about Twice Commerce – Easy Rental Booking System