
FareHarbor for WordPress Security & Risk Analysis
wordpress.org/plugins/fareharborEasily add FareHarbor reservation calendars, booking embeds, and buttons to your site.
Is FareHarbor for WordPress Safe to Use in 2026?
Generally Safe
Score 99/100FareHarbor for WordPress has a strong security track record. Known vulnerabilities have been patched promptly.
The FareHarbor plugin v3.6.12 exhibits a mixed security posture. While the static analysis reveals a lack of dangerous functions, raw SQL queries, file operations, and external HTTP requests, indicating good coding practices in certain areas, significant concerns arise from the insufficient output escaping. With only 13% of outputs properly escaped, there's a substantial risk of Cross-Site Scripting (XSS) vulnerabilities, allowing attackers to inject malicious scripts into web pages. The absence of nonce and capability checks on the identified entry points further exacerbates this risk by potentially exposing functionality to unauthorized users or automated attacks.
The vulnerability history is a critical concern. The plugin has a record of two medium-severity CVEs, both related to Cross-Site Scripting, with the most recent being in October 2023. The fact that these were medium severity and none are currently unpatched is positive, but the repeated nature of XSS vulnerabilities suggests a persistent weakness in how user input is handled and sanitized, which directly aligns with the low output escaping rate observed in the static analysis. The absence of any taint analysis flows is unusual for a plugin with a history of XSS, suggesting either the taint analysis tool was not fully effective or the identified XSS issues were subtle.
In conclusion, while the plugin demonstrates strengths in avoiding certain common vulnerabilities like raw SQL and dangerous functions, the low output escaping rate and historical XSS vulnerabilities present a significant risk. The lack of explicit authorization checks on entry points also contributes to potential security gaps. Developers should prioritize addressing the output escaping and input sanitization to mitigate XSS risks and ensure all entry points have appropriate authorization checks.
Key Concerns
- Low output escaping rate
- No nonce checks on entry points
- No capability checks on entry points
- History of medium severity CVEs (XSS)
FareHarbor for WordPress Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
FareHarbor for WordPress <= 3.6.7 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
FareHarbor for WordPress <= 3.6.6 - Authenticated (Administrator+) Stored Cross-Site Scripting
FareHarbor for WordPress Code Analysis
Output Escaping
FareHarbor for WordPress Attack Surface
Shortcodes 4
WordPress Hooks 5
Maintenance & Trust
FareHarbor for WordPress Maintenance & Trust
Maintenance Signals
Community Trust
FareHarbor for WordPress Alternatives
Starboard Suite Reservation Calendars
starboard-suite-reservation-calendars
Easily add Starboard Suite booking calendars to your WordPress site
CP Reservation Calendar
cp-reservation-calendar
CP Reservation Calendar is a booking calendar that allows selecting dates - ex: check-in and check-out dates - for a reservation.
WP Booking System – Booking Calendar
wp-booking-system
The booking calendar plugin for WordPress. Get easy online booking with this lightweight and powerful booking calendar.
Booking calendar, Appointment Booking System
booking-calendar
Booking calendar plugin is an awesome tool for creating appointment booking calendars and Scheduling systems in a few minutes.
Pinpoint Booking System – Version 2
booking-system
Book anything, anytime, anywhere.
FareHarbor for WordPress Developer Profile
1 plugin · 9K total installs
How We Detect FareHarbor for WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fareharbor/js/fareharbor.js/wp-content/plugins/fareharbor/css/fareharbor.csshttps://fareharbor.com/embeds/api/v1/https://fh-kit.com/buttons/v1/https://fh-kit.com/buttons/v2/fareharbor/js/fareharbor.js?ver=fareharbor/css/fareharbor.css?ver=HTML / DOM Fingerprints
fh-calendarfh-embedfh-widget<!-- FareHarbor plugin activated --><!-- FareHarbor Booking Button -->data-fareharbor-shortnamedata-fareharbor-bookable-onlydata-fareharbor-idwindow.fareharborvar fareharbor_settings/wp-json/fareharbor/[fareharbor][lightframe][partners][itemgrid]