
FoodBook Lite – Online Food Ordering System Security & Risk Analysis
wordpress.org/plugins/foodbook-light-online-food-ordering-systemShort Description: WooCommerce-based food ordering and restaurant delivery management plugin.
Is FoodBook Lite – Online Food Ordering System Safe to Use in 2026?
Generally Safe
Score 100/100FoodBook Lite – Online Food Ordering System has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "foodbook-light-online-food-ordering-system" plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices regarding SQL queries, utilizing prepared statements for all three identified queries, and a high percentage of properly escaped output. It also incorporates nonce and capability checks, albeit not consistently across all entry points. The absence of any recorded vulnerabilities or CVEs is a significant strength.
However, a major concern lies in the substantial attack surface exposed by 34 unprotected AJAX handlers. This large number of unauthenticated entry points presents a significant risk, as attackers could potentially exploit these handlers without needing to log in or possess any specific privileges. While the taint analysis did not reveal critical or high-severity vulnerabilities, the presence of flows with unsanitized paths warrants attention, even if their severity is not explicitly defined as critical or high. The plugin also makes external HTTP requests, which could be a vector for SSRF or other attacks if not handled carefully.
In conclusion, while the plugin benefits from secure SQL handling and a clean vulnerability history, the extensive unprotected AJAX endpoints are a critical weakness. This necessitates immediate attention to implement proper authentication and authorization checks on these handlers to mitigate the risk of unauthorized access and potential exploitation.
Key Concerns
- Large attack surface without auth
- Flows with unsanitized paths
- External HTTP requests
FoodBook Lite – Online Food Ordering System Security Vulnerabilities
FoodBook Lite – Online Food Ordering System Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
FoodBook Lite – Online Food Ordering System Attack Surface
AJAX Handlers 34
Shortcodes 1
WordPress Hooks 45
Maintenance & Trust
FoodBook Lite – Online Food Ordering System Maintenance & Trust
Maintenance Signals
Community Trust
FoodBook Lite – Online Food Ordering System Alternatives
RestroFood Lite – Online Food Ordering and Restaurant Management Plugin For WooCommerce
restrofood-lite
Short Description: Complete online food ordering system for restaurants built with WooCommerce.
FoodOrd – Online Food Ordering System
foodord
Transform your WooCommerce store into a food ordering system with delivery, pickup, toppings, and optional desktop app.
Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin
orderable
Take your restaurant/food business online with the online ordering system plugin for WordPress, Orderable.
WPCafe – Restaurant Menu, Online Food Ordering and Reservation Booking Solution
wp-cafe
Complete restaurant solution for restaurant menus, online food ordering, delivery, reservations and booking
Food Menu – Restaurant Menu & Online Ordering for WooCommerce
tlp-food-menu
A Simple Food & Restaurant Menu Display Plugin for Restaurant, Cafes, Fast Food, Coffee House with WooCommerce Online Ordering.
FoodBook Lite – Online Food Ordering System Developer Profile
11 plugins · 3K total installs
How We Detect FoodBook Lite – Online Food Ordering System
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/foodbook-light-online-food-ordering-system/admin/assets/css/style.css/wp-content/plugins/foodbook-light-online-food-ordering-system/admin/assets/js/script.js/wp-content/plugins/foodbook-light-online-food-ordering-system/admin/assets/js/script.jsfoodbook-light-online-food-ordering-system/admin/assets/css/style.css?ver=foodbook-light-online-food-ordering-system/admin/assets/js/script.js?ver=HTML / DOM Fingerprints
foodbooklite_admin_notice<!-- Classic Checkout page for foodbook --><!-- Classic Checkout page for foodbook --><!-- FoodBookLite requires the WooCommerce plugin to be installed and active. -->data-product-limitfoodbooklite_ajax_object[foodbooklite_products][foodbooklite_categories][foodbooklite_search][foodbooklite_cart]