Feature Add-Ons For Booked Security & Risk Analysis

wordpress.org/plugins/feature-add-ons-for-booked

Extending the capabilities of Boxy Studio's Booked Appointments plugin.

40 active installs v1.0.1 PHP 7.2+ WP 5.3+ Updated Apr 28, 2023
booked-appointmentsboxy-studioextension-add-ons
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Feature Add-Ons For Booked Safe to Use in 2026?

Generally Safe

Score 85/100

Feature Add-Ons For Booked has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The plugin 'feature-add-ons-for-booked' v1.0.1 exhibits a generally strong security posture based on the static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points is a significant strength, indicating a minimal attack surface. The code also demonstrates good practices with 100% of SQL queries using prepared statements and a high percentage of output escaping. Nonce checks are present, further contributing to security. However, the analysis did identify two flows with unsanitized paths during taint analysis. While these did not escalate to critical or high severity, they represent potential weaknesses that could be exploited under certain conditions. Furthermore, the complete lack of recorded vulnerabilities in its history, while positive, could also imply limited historical testing or a very small user base, making it difficult to draw firm conclusions about its long-term resilience. Overall, the plugin has a good foundation, but the identified unsanitized paths warrant attention to ensure complete security.

Key Concerns

  • Unsanitized paths found in taint analysis
  • Capability checks are missing
  • Some output not properly escaped
Vulnerabilities
None known

Feature Add-Ons For Booked Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Feature Add-Ons For Booked Release Timeline

v1.0.1Current
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Feature Add-Ons For Booked Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
48 escaped
Nonce Checks
3
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

76% escaped63 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

3 flows2 with unsanitized paths
<view-appointments> (admin\view-appointments.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Feature Add-Ons For Booked Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_enqueue_scriptsincludes\class-faofb.php:50
actionadmin_menuincludes\class-faofb.php:52
actionadmin_initincludes\class-faofb.php:54
Maintenance & Trust

Feature Add-Ons For Booked Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedApr 28, 2023
PHP min version7.2
Downloads1K

Community Trust

Rating40/100
Number of ratings1
Active installs40
Alternatives

Feature Add-Ons For Booked Alternatives

No alternatives data available yet.

Developer Profile

Feature Add-Ons For Booked Developer Profile

alvinmuthui

3 plugins · 40 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Feature Add-Ons For Booked

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/feature-add-ons-for-booked/assets/css/css.css/wp-content/plugins/feature-add-ons-for-booked/assets/js/js.js/wp-content/plugins/feature-add-ons-for-booked/assets/css/jquery-ui.css/wp-content/plugins/feature-add-ons-for-booked/assets/admin/css/faofb-style.min.css
Script Paths
/wp-content/plugins/feature-add-ons-for-booked/assets/js/js.js
Version Parameters
feature-add-ons-for-booked/assets/css/css.css?ver=feature-add-ons-for-booked/assets/js/js.js?ver=feature-add-ons-for-booked/assets/css/jquery-ui.css?ver=feature-add-ons-for-booked/assets/admin/css/faofb-style.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
apt-containerapt-panel-headapt-panel-bodyapt-tableapt-export-btn
HTML Comments
<!-- View Appointments --><!-- Adds all appointment form nonce. -->
Data Attributes
name="faofb_field_check"name="booked_addon_csv"name="faofb_get_check"
FAQ

Frequently Asked Questions about Feature Add-Ons For Booked