
Experience & Activities Booking System Security & Risk Analysis
wordpress.org/plugins/experience-activities-booking-systemExperience & Activities Booking System by uppliv allows you to connect your Wordpress installation with your uppliv.com account.
Is Experience & Activities Booking System Safe to Use in 2026?
Generally Safe
Score 85/100Experience & Activities Booking System has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "experience-activities-booking-system" plugin v1.2.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and performing a reasonable amount of output escaping. The absence of any recorded vulnerabilities or CVEs in its history is also a strong positive indicator, suggesting a commitment to secure development or a lack of past exploitable flaws.
However, significant concerns arise from the attack surface analysis. Two AJAX handlers are present without any authentication checks, creating potential entry points for unauthorized actions. While no critical or high severity taint flows were detected, the lack of capability checks on these AJAX endpoints means that any authenticated user could potentially trigger these functions, which could lead to unintended consequences if not properly validated and sanitized internally. The plugin also has a limited number of entry points and no bundled libraries, which are generally positive signs.
In conclusion, the plugin has a solid foundation in terms of SQL security and output sanitization. The primary weakness lies in the unprotected AJAX handlers, which represent a clear security risk. While the historical lack of vulnerabilities is encouraging, the presence of these unprotected entry points warrants attention and potential remediation. The current version shows a balance between good security practices and specific areas of concern.
Key Concerns
- Unprotected AJAX handlers
- Missing capability checks on AJAX
- 70% output escaping (30% unescaped)
Experience & Activities Booking System Security Vulnerabilities
Experience & Activities Booking System Code Analysis
Output Escaping
Data Flow Analysis
Experience & Activities Booking System Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 10
Maintenance & Trust
Experience & Activities Booking System Maintenance & Trust
Maintenance Signals
Community Trust
Experience & Activities Booking System Alternatives
Online Scheduling and Appointment Booking System – Bookly
bookly-responsive-appointment-booking-tool
Appointment booking system for WordPress — schedule appointments, manage calendars, send reminders, take payments. Start booking today!
WP Booking System – Booking Calendar
wp-booking-system
The booking calendar plugin for WordPress. Get easy online booking with this lightweight and powerful booking calendar.
Booking Activities
booking-activities
Reservation system specialized in activities: sports, leisure, courses, events, tourism, and more! Works great with WooCommerce.
Booking calendar, Appointment Booking System
booking-calendar
Booking calendar plugin is an awesome tool for creating appointment booking calendars and Scheduling systems in a few minutes.
Pinpoint Booking System – Version 2
booking-system
Book anything, anytime, anywhere.
Experience & Activities Booking System Developer Profile
1 plugin · 0 total installs
How We Detect Experience & Activities Booking System
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/experience-activities-booking-system/assets/eabs_admin-style.css/wp-content/plugins/experience-activities-booking-system/assets/eabs_admin-script.js/wp-content/plugins/experience-activities-booking-system/assets/eabs_admin-script.jsHTML / DOM Fingerprints
eabs_admin_layout_main_headereabs_admin_layout_main_bodydata-eabs_shortcode_domaindata-eabs_shortcode_cart_pagedata-eabs_shortcode_checkout_pagedata-eabs_enable_api_integrationdata-eabs_enable_search_filterdata-eabs_booking_page+2 moreeabs_admin_object