GetYourGuide Ticketing Security & Risk Analysis

wordpress.org/plugins/getyourguide-ticketing

Official GetYourGuide's plugin to easily add a ticketing solution to your Wordpress website

60 active installs v1.0.6 PHP + WP 3.0.1+ Updated Nov 28, 2022
booking-enginegetyourguidemuseumticketticketing
85
A · Safe
CVEs total1
Unpatched0
Last CVESep 18, 2022
Safety Verdict

Is GetYourGuide Ticketing Safe to Use in 2026?

Generally Safe

Score 85/100

GetYourGuide Ticketing has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 18, 2022Updated 3yr ago
Risk Assessment

The static analysis of the 'getyourguide-ticketing' plugin v1.0.6 indicates a generally strong security posture. There are no identified direct entry points such as AJAX handlers, REST API routes, shortcodes, or cron events exposed to users. The code further demonstrates good practices by using prepared statements for all SQL queries and properly escaping all output, with no file operations or external HTTP requests detected. The absence of dangerous functions and the lack of any taint analysis findings with unsanitized paths are also positive indicators.

However, the plugin's vulnerability history presents a significant concern. With one known CVE, specifically a medium-severity Cross-site Scripting (XSS) vulnerability that was last patched on 2022-09-18, there is a clear indication of past security weaknesses. While there are currently no unpatched vulnerabilities, the existence of a past XSS issue suggests that inputs may not always be adequately validated or neutralized, potentially leaving the door open for similar future vulnerabilities if not rigorously addressed.

In conclusion, while the current version of the plugin appears to have a solid technical foundation with no immediate code-level risks identified in the static analysis, the past XSS vulnerability necessitates vigilance. The absence of certain security checks like nonce and capability checks, while not presenting an immediate attack vector due to the limited attack surface, could become a concern if new entry points are introduced in future updates. The focus should remain on ensuring that all historical vulnerabilities are permanently remediated and that future development maintains this high standard of secure coding.

Key Concerns

  • Medium severity CVE in history
  • No capability checks
  • No nonce checks
Vulnerabilities
1

GetYourGuide Ticketing Security Vulnerabilities

CVEs by Year

1 CVE in 2022
2022
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2022-3609medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

GetYourGuide Ticketing <= 1.0.2 - Authenticated (Admin+) Stored Cross-Site Scripting

Sep 18, 2022 Patched in 1.0.3 (492d)
Code Analysis
Analyzed Mar 16, 2026

GetYourGuide Ticketing Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped7 total outputs
Attack Surface

GetYourGuide Ticketing Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionplugins_loadedincludes\class-getyourguide-ticketing.php:144
actionadmin_enqueue_scriptsincludes\class-getyourguide-ticketing.php:159
actionadmin_enqueue_scriptsincludes\class-getyourguide-ticketing.php:160
actionadmin_menuincludes\class-getyourguide-ticketing.php:161
actionadmin_initincludes\class-getyourguide-ticketing.php:162
actionwp_enqueue_scriptsincludes\class-getyourguide-ticketing.php:177
actionwp_enqueue_scriptsincludes\class-getyourguide-ticketing.php:178
filterscript_loader_tagpublic\class-getyourguide-ticketing-public.php:93
Maintenance & Trust

GetYourGuide Ticketing Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 28, 2022
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs60
Developer Profile

GetYourGuide Ticketing Developer Profile

Marcello Romanelli

1 plugin · 60 total installs

69
trust score
Avg Security Score
85/100
Avg Patch Time
492 days
View full developer profile
Detection Fingerprints

How We Detect GetYourGuide Ticketing

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/getyourguide-ticketing/css/getyourguide-ticketing-admin.css/wp-content/plugins/getyourguide-ticketing/js/getyourguide-ticketing-admin.js
Script Paths
/wp-content/plugins/getyourguide-ticketing/js/getyourguide-ticketing-admin.js
Version Parameters
getyourguide-ticketing/css/getyourguide-ticketing-admin.css?ver=getyourguide-ticketing/js/getyourguide-ticketing-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-gyg-partner-hashdata-gyg-currency
FAQ

Frequently Asked Questions about GetYourGuide Ticketing