
Feature Add-Ons For Booked Security & Risk Analysis
wordpress.org/plugins/feature-add-ons-for-bookedExtending the capabilities of Boxy Studio's Booked Appointments plugin.
Is Feature Add-Ons For Booked Safe to Use in 2026?
Generally Safe
Score 85/100Feature Add-Ons For Booked has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'feature-add-ons-for-booked' v1.0.1 exhibits a generally strong security posture based on the static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a minimal attack surface. The code also demonstrates good practices with 100% of SQL queries using prepared statements and a high percentage of output escaping. Nonce checks are present, further contributing to security. However, the analysis did identify two flows with unsanitized paths during taint analysis. While these did not escalate to critical or high severity, they represent potential weaknesses that could be exploited under certain conditions. Furthermore, the complete lack of recorded vulnerabilities in its history, while positive, could also imply limited historical testing or a very small user base, making it difficult to draw firm conclusions about its long-term resilience. Overall, the plugin has a good foundation, but the identified unsanitized paths warrant attention to ensure complete security.
Key Concerns
- Unsanitized paths found in taint analysis
- Capability checks are missing
- Some output not properly escaped
Feature Add-Ons For Booked Security Vulnerabilities
Feature Add-Ons For Booked Release Timeline
Feature Add-Ons For Booked Code Analysis
Output Escaping
Data Flow Analysis
Feature Add-Ons For Booked Attack Surface
WordPress Hooks 3
Maintenance & Trust
Feature Add-Ons For Booked Maintenance & Trust
Maintenance Signals
Community Trust
Feature Add-Ons For Booked Alternatives
No alternatives data available yet.
Feature Add-Ons For Booked Developer Profile
3 plugins · 40 total installs
How We Detect Feature Add-Ons For Booked
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/feature-add-ons-for-booked/assets/css/css.css/wp-content/plugins/feature-add-ons-for-booked/assets/js/js.js/wp-content/plugins/feature-add-ons-for-booked/assets/css/jquery-ui.css/wp-content/plugins/feature-add-ons-for-booked/assets/admin/css/faofb-style.min.css/wp-content/plugins/feature-add-ons-for-booked/assets/js/js.jsfeature-add-ons-for-booked/assets/css/css.css?ver=feature-add-ons-for-booked/assets/js/js.js?ver=feature-add-ons-for-booked/assets/css/jquery-ui.css?ver=feature-add-ons-for-booked/assets/admin/css/faofb-style.min.css?ver=HTML / DOM Fingerprints
apt-containerapt-panel-headapt-panel-bodyapt-tableapt-export-btn<!-- View Appointments --><!-- Adds all appointment form nonce. -->name="faofb_field_check"name="booked_addon_csv"name="faofb_get_check"