
GetYourGuide WordPress plugin Security & Risk Analysis
wordpress.org/plugins/getyourguide-widgetGet paid to travel. Make money by sharing activities with your readers. Share GetYourGuide's incredible selection of attractions, tours and activ …
Is GetYourGuide WordPress plugin Safe to Use in 2026?
Generally Safe
Score 85/100GetYourGuide WordPress plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The getyourguide-widget plugin v1.3.10 exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history suggest a well-maintained and secure codebase over time. Furthermore, the plugin demonstrates good development practices by utilizing prepared statements for all SQL queries and refraining from file operations or external HTTP requests, which are common sources of vulnerabilities.
However, there are specific areas of concern within the static analysis. The presence of the `create_function` dangerous function is a significant red flag, as it can lead to arbitrary code execution if not handled with extreme care, although no specific exploit path was identified in the taint analysis. Additionally, while the plugin has capability checks, the absence of nonce checks on any potential entry points (though none were identified as unprotected) is a weakness that could be exploited if new entry points are added without proper security considerations.
While the lack of identified taint flows and a zero-day history are positive indicators, the presence of `create_function` and a less than ideal output escaping percentage (66%) represent potential vulnerabilities. The overall security posture is good, but these specific code signals warrant attention and potential remediation to achieve a more robust security profile.
Key Concerns
- Use of dangerous function: create_function
- Output escaping below 80%
- Lack of nonce checks
GetYourGuide WordPress plugin Security Vulnerabilities
GetYourGuide WordPress plugin Code Analysis
Dangerous Functions Found
Output Escaping
GetYourGuide WordPress plugin Attack Surface
WordPress Hooks 13
Maintenance & Trust
GetYourGuide WordPress plugin Maintenance & Trust
Maintenance Signals
Community Trust
GetYourGuide WordPress plugin Alternatives
Booking.com Product Helper
bookingcom-product-helper
The Booking.com Product Helper allows you to embed any Booking.com affiliate product anywhere on your website.
Average Travel Costs
average-travel-costs
Displays average daily travel costs from Budget Your Trip.
Cheap Flights By Kiwi.com
kiwi-com-widget
Are you a travel writer, blogger, photographer, or do you just have a website where you share travel related content? Do you have many website visitor …
Classic Widgets
classic-widgets
Enables the previous "classic" widgets settings screens in Appearance - Widgets and the Customizer. Disables the block editor from managing widgets.
Widget Logic
widget-logic
Widget Logic lets you control on which pages widgets appear using WP's conditional tags.
GetYourGuide WordPress plugin Developer Profile
4 plugins · 490 total installs
How We Detect GetYourGuide WordPress plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/getyourguide-widget/dist/post.js/wp-content/plugins/getyourguide-widget/dist/main.jshttps://widget.getyourguide.com/dist/pa.umd.production.min.jsHTML / DOM Fingerprints
getyourguide-widget-classdata-gyg-partner-id>> This plugin does not support adding widgets via the wordpress appearance menu. To use this plugin, please add the widgets within your posts, by adding new blocks. <<GetYourGuide Widget Plugin