Free Booking System Security & Risk Analysis

wordpress.org/plugins/free-booking-system

Automate your booking process by allowing your customers to choose a slot that works best for them and book in seconds.

10 active installs v1.1 PHP 7.4+ WP 5.9+ Updated Dec 6, 2022
appointment-bookingappointmentsbookingbooking-softwareclass-booking
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Free Booking System Safe to Use in 2026?

Generally Safe

Score 85/100

Free Booking System has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "free-booking-system" plugin v1.1 exhibits a strong security posture based on the provided static analysis. There are no detected dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. The absence of file operations and external HTTP requests further reduces the attack surface. Notably, the plugin has no recorded vulnerability history, with zero known CVEs, indicating a history of secure development or diligent patching.

However, a significant concern arises from the lack of any capability checks or nonce checks on its single shortcode entry point. While the attack surface is currently small and there are no unprotected entry points detected *at this moment*, this oversight leaves the plugin vulnerable to potential exploitation if malicious data is passed through the shortcode. The absence of taint analysis flows might be due to the limited entry points or the nature of the code, but it doesn't negate the risk posed by the missing authorization checks.

In conclusion, the plugin demonstrates good coding practices in areas like SQL handling and output escaping, and its vulnerability history is excellent. The primary weakness is the lack of authorization checks on its shortcode. While currently presenting a low immediate risk due to the limited attack surface and absence of known vulnerabilities, this gap could be exploited in the future. It is recommended to implement capability checks on the shortcode to further harden its security.

Key Concerns

  • Shortcode missing capability checks
  • Shortcode missing nonce checks
Vulnerabilities
None known

Free Booking System Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Free Booking System Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
3 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped3 total outputs
Attack Surface

Free Booking System Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[bookonline_panel] bookonlinepanel.php:247
WordPress Hooks 4
actionadmin_initbookonlinepanel.php:38
actionadmin_menubookonlinepanel.php:39
actionadmin_headbookonlinepanel.php:40
filterwp_kses_allowed_htmlbookonlinepanel.php:266
Maintenance & Trust

Free Booking System Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 6, 2022
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Free Booking System Developer Profile

Ikaroa

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Free Booking System

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/free-booking-system/img/booking_software.png/wp-content/plugins/free-booking-system/img/icon.png

HTML / DOM Fingerprints

CSS Classes
book-top-panelbook-online-panelbook-panel-setup
Data Attributes
data-tab
Shortcode Output
[bookonline]
FAQ

Frequently Asked Questions about Free Booking System