Hospedajes España – HOSTPN Security & Risk Analysis

wordpress.org/plugins/hostpn

Allow you to ask for, save and send the information required by spanish Royal Decree 933/2021, of October 26.

0 active installs v1.0.0 PHP + WP 3.5+ Updated Jan 9, 2026
check-inhospedajes-espanahost-registerhostingspain
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hospedajes España – HOSTPN Safe to Use in 2026?

Generally Safe

Score 100/100

Hospedajes España – HOSTPN has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The hostpn v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of any AJAX handlers, REST API routes, shortcodes, or cron events significantly limits the plugin's attack surface to zero, and importantly, all identified entry points are reported as protected. The code also demonstrates good practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and generally escaping output effectively (94%). Nonce and capability checks are present, indicating an awareness of WordPress security fundamentals. The plugin's vulnerability history is clean, with no known CVEs, which suggests a history of responsible development or a lack of past security scrutiny.

However, the taint analysis reveals a potential area of concern. Three out of four analyzed flows have unsanitized paths. While no critical or high severity issues were reported in the taint analysis, this indicates that there might be pathways within the code that could be manipulated by user input without proper sanitization, potentially leading to unexpected behavior or even security vulnerabilities if exploited in conjunction with other factors or future code changes. The fact that these paths are not classified as critical or high could be due to the limited attack surface and other security measures in place, but it still warrants attention. The absence of file operations and external HTTP requests further solidifies the plugin's contained nature.

In conclusion, hostpn v1.0.0 appears to be a well-developed plugin from a security perspective, with a minimal attack surface and good adherence to core WordPress security best practices. The primary weakness identified is the presence of unsanitized paths in the taint analysis, which, while not currently manifesting as severe vulnerabilities, represents a latent risk that should be investigated and remediated to ensure the plugin's long-term security and robustness. The clean vulnerability history is a positive indicator, but it is essential to address the identified taint flow issues proactively.

Key Concerns

  • Unsanitized paths in taint analysis
Vulnerabilities
None known

Hospedajes España – HOSTPN Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Hospedajes España – HOSTPN Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
82
1299 escaped
Nonce Checks
7
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped1381 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

4 flows3 with unsanitized paths
hostpn_ajax_server (includes\class-hostpn-ajax.php:19)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Hospedajes España – HOSTPN Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actioninithostpn.php:433
filtersingle_templateincludes\class-hostpn-post-type-accommodation.php:765
filterarchive_templateincludes\class-hostpn-post-type-accommodation.php:766
actionpre_get_postsincludes\class-hostpn-post-type-guest.php:306
actionwp_enqueue_scriptsincludes\class-hostpn-selector.php:29
actionadmin_enqueue_scriptsincludes\class-hostpn-selector.php:30
Maintenance & Trust

Hospedajes España – HOSTPN Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 9, 2026
PHP min version
Downloads704

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Hospedajes España – HOSTPN Developer Profile

Félix Martínez

8 plugins · 20 total installs

93
trust score
Avg Security Score
99/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hospedajes España – HOSTPN

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hostpn/css/admin.css/wp-content/plugins/hostpn/css/guest.css/wp-content/plugins/hostpn/css/accommodation.css/wp-content/plugins/hostpn/css/hostpn.css/wp-content/plugins/hostpn/js/guest.js/wp-content/plugins/hostpn/js/accommodation.js/wp-content/plugins/hostpn/js/hostpn.js
Script Paths
/wp-content/plugins/hostpn/js/guest.js/wp-content/plugins/hostpn/js/accommodation.js/wp-content/plugins/hostpn/js/hostpn.js
Version Parameters
hostpn/css/admin.css?ver=hostpn/css/guest.css?ver=hostpn/css/accommodation.css?ver=hostpn/css/hostpn.css?ver=hostpn/js/guest.js?ver=hostpn/js/accommodation.js?ver=hostpn/js/hostpn.js?ver=

HTML / DOM Fingerprints

CSS Classes
hostpn-guest-formhostpn-accommodation-formhostpn-section-titlehostpn-feature-item
HTML Comments
<!-- IMPORTANT: If you want to access the REST API, you need to enable it --><!-- This plugin doesn't have a REST API endpoints --><!-- If you are a developer and you want to add a new feature in the plugin, please read the documentation in the plugin folder
Data Attributes
data-hostpn-iddata-hostpn-type
JS Globals
hostpn_dataHOSTPN_VERSIONHOSTPN_DIRHOSTPN_URL
Shortcode Output
[hostpn_guest_form][hostpn_accommodation_form]
FAQ

Frequently Asked Questions about Hospedajes España – HOSTPN