HostAway Connector Security & Risk Analysis

wordpress.org/plugins/hostaway-connector

Display real-time Hostaway listings, availability calendars, and enable direct bookings using the Hostaway API — with no local data storage.

60 active installs v1.0.2 PHP 7.4+ WP 5.0+ Updated Jan 30, 2026
hostawayhostaway-bookinghostaway-calendarhostaway-connectorhostaway-listings
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is HostAway Connector Safe to Use in 2026?

Generally Safe

Score 100/100

HostAway Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The hostaway-connector plugin version 1.0.2 demonstrates a generally strong security posture based on the provided static analysis. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events with exposed entry points significantly limits the potential attack surface. The code also shows a commitment to secure coding practices, with 100% of SQL queries utilizing prepared statements and a very high rate of proper output escaping (98%). Furthermore, the presence of nonce and capability checks, although limited in number, indicates an awareness of common WordPress security mechanisms.

However, there are minor areas for attention. The plugin makes three external HTTP requests, which, while not inherently a vulnerability, represent a potential risk if the target endpoints are compromised or if data is transmitted insecurely. The taint analysis revealing zero flows with unsanitized paths is a very positive indicator, suggesting no obvious vulnerabilities in data handling. The plugin's vulnerability history being entirely clear, with no recorded CVEs, is an excellent sign of its current security and maintenance. Despite the low number of entry points, the lack of any, even if protected, could be interpreted as either a very focused plugin or a missed opportunity for certain functionalities if not handled with extreme care.

In conclusion, hostaway-connector v1.0.2 appears to be a well-secured plugin with a minimal attack surface and good coding practices. The absence of known vulnerabilities is a significant strength. The only points of minor concern are the external HTTP requests, which should be monitored for secure implementation. The overall security is high, but continuous vigilance, especially regarding external dependencies, is always recommended.

Key Concerns

  • External HTTP requests detected
Vulnerabilities
None known

HostAway Connector Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

HostAway Connector Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
165 escaped
Nonce Checks
4
Capability Checks
2
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

98% escaped168 total outputs
Attack Surface

HostAway Connector Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionplugins_loadedhostaway-connector.php:111
actionadmin_menuincludes\class-haway-admin.php:22
actionadmin_initincludes\class-haway-admin.php:23
actionupdate_option_haway_listings_per_pageincludes\class-haway-admin.php:24
actionadmin_noticesincludes\class-haway-admin.php:25
actionadmin_post_haway_approve_apiincludes\class-haway-admin.php:26
actionadmin_footerincludes\class-haway-admin.php:32
actionwp_enqueue_scriptsincludes\class-haway-frontend.php:75
actioninitincludes\class-haway-frontend.php:79
filterquery_varsincludes\class-haway-frontend.php:83
filterredirect_canonicalincludes\class-haway-frontend.php:87
Maintenance & Trust

HostAway Connector Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 30, 2026
PHP min version7.4
Downloads641

Community Trust

Rating0/100
Number of ratings0
Active installs60
Alternatives

HostAway Connector Alternatives

No alternatives data available yet.

Developer Profile

HostAway Connector Developer Profile

610 Web Lab

1 plugin · 60 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect HostAway Connector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hostaway-connector/assets/css/jquery-ui.css/wp-content/plugins/hostaway-connector/assets/css/fonts.css/wp-content/plugins/hostaway-connector/assets/css/slick.css/wp-content/plugins/hostaway-connector/assets/css/slick-theme.css/wp-content/plugins/hostaway-connector/assets/css/style.css/wp-content/plugins/hostaway-connector/assets/js/slick.js/wp-content/plugins/hostaway-connector/assets/js/script.js
Script Paths
/wp-content/plugins/hostaway-connector/assets/js/slick.js/wp-content/plugins/hostaway-connector/assets/js/script.js
Version Parameters
hostaway-connector/assets/css/jquery-ui.css?ver=hostaway-connector/assets/css/fonts.css?ver=hostaway-connector/assets/css/slick.css?ver=hostaway-connector/assets/css/slick-theme.css?ver=hostaway-connector/assets/css/style.css?ver=hostaway-connector/assets/js/slick.js?ver=hostaway-connector/assets/js/script.js?ver=

HTML / DOM Fingerprints

Shortcode Output
[hostaway_listing]
FAQ

Frequently Asked Questions about HostAway Connector