Guestplan Booking Widget Security & Risk Analysis

wordpress.org/plugins/guestplan-booking-widget

Turn website visitors into guests with our Guestplan Booking Widget for your website. Install our booking widget on your website and turn your visitor …

1K active installs v1.0.11 PHP + WP 5.0+ Updated Jan 10, 2026
bookingsreservationsrestaurant
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Guestplan Booking Widget Safe to Use in 2026?

Generally Safe

Score 100/100

Guestplan Booking Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The guestplan-booking-widget plugin v1.0.11 exhibits a generally strong security posture based on the provided static analysis. The plugin has no recorded vulnerabilities in its history, indicating a commitment to security or a lack of past exploitable flaws. The static analysis reveals a small attack surface with zero entry points and no code signals indicating immediately exploitable vulnerabilities such as dangerous functions, raw SQL queries, file operations, or external HTTP requests. The use of prepared statements for all SQL queries is a significant strength. However, a concern arises from the low percentage of properly escaped output (37%), which could leave the plugin susceptible to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient sanitization before being displayed. While the capability check is present, the absence of nonce checks for AJAX or other entry points, if they existed, could be a weakness. Taint analysis showed no critical or high severity issues, further reinforcing the low risk of direct code execution or sensitive data exposure through tainted inputs.

Despite the lack of known vulnerabilities and a limited attack surface, the low output escaping rate is a notable weakness that could be exploited. The absence of any recorded vulnerabilities in the past is positive but does not guarantee future security, especially given the unescaped output. The plugin demonstrates good practices in terms of SQL and avoiding dangerous functions, but it needs improvement in ensuring all output is properly escaped to prevent potential XSS attacks. Overall, the plugin is assessed as low to medium risk, with the primary area for improvement being output sanitization.

Key Concerns

  • Low percentage of properly escaped output
Vulnerabilities
None known

Guestplan Booking Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Guestplan Booking Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
19
11 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

37% escaped30 total outputs
Attack Surface

Guestplan Booking Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedincludes\class-guestplan.php:146
actionadmin_enqueue_scriptsincludes\class-guestplan.php:162
actionadmin_enqueue_scriptsincludes\class-guestplan.php:163
actionadmin_noticesincludes\class-guestplan.php:164
actionadmin_menuincludes\class-guestplan.php:167
actionadmin_initincludes\class-guestplan.php:168
actionwp_enqueue_scriptsincludes\class-guestplan.php:187
actionwp_enqueue_scriptsincludes\class-guestplan.php:188
actionwp_headincludes\class-guestplan.php:189
Maintenance & Trust

Guestplan Booking Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 10, 2026
PHP min version
Downloads8K

Community Trust

Rating80/100
Number of ratings2
Active installs1K
Developer Profile

Guestplan Booking Widget Developer Profile

guestplan

1 plugin · 1K total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Guestplan Booking Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/guestplan-booking-widget/assets/css/guestplan-public.css/wp-content/plugins/guestplan-booking-widget/assets/js/guestplan-public.js
Script Paths
assets/js/guestplan-public.js
Version Parameters
guestplan-booking-widget/assets/css/guestplan-public.css?ver=guestplan-booking-widget/assets/js/guestplan-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
guestplan-widget-wrapper
HTML Comments
Guestplan Booking WidgetGuestplanGuestplan Booking Widget
Data Attributes
data-guestplan-widget
JS Globals
guestplanBookingWidgetSettings
Shortcode Output
[guestplan]
FAQ

Frequently Asked Questions about Guestplan Booking Widget