
Experitus Booking Form Security & Risk Analysis
wordpress.org/plugins/experitus-formThe WordPress Plugin For Embedding Experitus Booking Forms On Your Website.
Is Experitus Booking Form Safe to Use in 2026?
Generally Safe
Score 85/100Experitus Booking Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The experitus-form plugin version 0.4 exhibits a mixed security posture. On the positive side, the plugin has no known CVEs and does not appear to use dangerous functions or direct SQL queries. It also implements nonce and capability checks on some entry points, and all SQL queries are prepared. However, there are significant concerns regarding output escaping and taint analysis. Only 16% of outputs are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, one taint flow was found with an unsanitized path, which, while not classified as critical or high severity in the provided data, still represents a potential injection vector. The absence of recorded vulnerabilities historically might suggest a lack of rigorous security auditing or that past versions were not widely used, rather than inherent security. The small attack surface is a positive, but the lack of comprehensive sanitization for outputs and the presence of an unsanitized path are critical weaknesses that need immediate attention.
Key Concerns
- Low percentage of properly escaped output
- Taint flow with unsanitized path
Experitus Booking Form Security Vulnerabilities
Experitus Booking Form Code Analysis
Output Escaping
Data Flow Analysis
Experitus Booking Form Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Experitus Booking Form Maintenance & Trust
Maintenance Signals
Community Trust
Experitus Booking Form Alternatives
Checkfront Online Booking System
checkfront-wp-booking
The Premier Wordpress Plugin for Easy Online Booking of Tours, Activities, Rentals & Accommodations.
ClockPms
clocksky
Use ClockPms plugin to embed our Web Reservation System in to your wordpress site.
TourSys Connect
toursys-connect
Allows visitors to your website to make tour and transfer bookings directly into
WP Booking System – Booking Calendar
wp-booking-system
The booking calendar plugin for WordPress. Get easy online booking with this lightweight and powerful booking calendar.
WP Hotel Booking
wp-hotel-booking
WordPress Hotel Booking Plugin - A complete hotel booking reservation plugin for WordPress.
Experitus Booking Form Developer Profile
1 plugin · 10 total installs
How We Detect Experitus Booking Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/experitus-form/assets/css/experitus-form.css/wp-content/plugins/experitus-form/assets/js/experitus-form.jsHTML / DOM Fingerprints
<!-- EXPERITUS_FORM_START --><!-- EXPERITUS_FORM_END -->data-experitus-formexperitus_ajax_object[experitus_form]