Hotel Booking by Xfor Security & Risk Analysis

wordpress.org/plugins/hotel-booking-by-xfor

Hotel Booking - helps you to setup hotel booking system quickly, pleasantly and easily.

10 active installs v0.1.5 PHP 7.0+ WP 5.0+ Updated Feb 8, 2022
bookingbooking-enginehotelreservationroom
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Hotel Booking by Xfor Safe to Use in 2026?

Generally Safe

Score 85/100

Hotel Booking by Xfor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The plugin 'hotel-booking-by-xfor' version 0.1.5 exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs) and no critical or high-severity issues identified in taint analysis. The code also demonstrates good practices with a high percentage of properly escaped outputs and a reasonable number of nonce and capability checks. However, there are significant concerns regarding its attack surface. The presence of 6 AJAX handlers without authentication checks presents a clear risk, potentially allowing unauthorized actions. While the SQL queries are not all prepared, the percentage is moderate, and the absence of critical taint flows suggests this might not be an immediate high-risk issue. The lack of historical vulnerabilities is a positive indicator of developer attention, but the significant number of unprotected entry points remains a primary concern that overshadows these positive aspects. The plugin needs to address its unprotected AJAX handlers to improve its overall security.

Key Concerns

  • AJAX handlers without auth checks
  • SQL queries not fully prepared
Vulnerabilities
None known

Hotel Booking by Xfor Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Hotel Booking by Xfor Release Timeline

v0.1.5Current
v0.1.4
v0.1.3
v0.1.2
v0.1.1
Code Analysis
Analyzed Mar 16, 2026

Hotel Booking by Xfor Code Analysis

Dangerous Functions
0
Raw SQL Queries
20
16 prepared
Unescaped Output
10
57 escaped
Nonce Checks
13
Capability Checks
18
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

44% prepared36 total queries

Output Escaping

85% escaped67 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

4 flows
xfor_switch_room_status (includes\ajax.php:230)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
6 unprotected

Hotel Booking by Xfor Attack Surface

Entry Points26
Unprotected6

AJAX Handlers 25

authwp_ajax_xfor_dashboardincludes\ajax.php:119
authwp_ajax_xfor_get_roomsincludes\ajax.php:171
authwp_ajax_xfor_add_roomincludes\ajax.php:200
authwp_ajax_xfor_delete_roomincludes\ajax.php:224
authwp_ajax_xfor_switch_room_statusincludes\ajax.php:253
authwp_ajax_xfor_update_roomincludes\ajax.php:280
authwp_ajax_xfor_get_ordersincludes\ajax.php:311
authwp_ajax_xfor_delete_orderincludes\ajax.php:335
authwp_ajax_xfor_get_room_typesincludes\ajax.php:373
authwp_ajax_xfor_add_room_typeincludes\ajax.php:411
authwp_ajax_xfor_del_room_typeincludes\ajax.php:453
authwp_ajax_xfor_get_room_typeincludes\ajax.php:512
authwp_ajax_xfor_edit_room_typeincludes\ajax.php:556
authwp_ajax_xfor_upload_imagesincludes\ajax.php:668
authwp_ajax_xfor_delete_imageincludes\ajax.php:749
authwp_ajax_xfor_get_room_type_imagesincludes\ajax.php:783
noprivwp_ajax_xfor_get_room_type_imagesincludes\ajax.php:784
authwp_ajax_xfor_get_settingsincludes\ajax.php:826
authwp_ajax_xfor_store_settingsincludes\ajax.php:875
authwp_ajax_xfor_checkincludes\ajax.php:912
noprivwp_ajax_xfor_checkincludes\ajax.php:913
authwp_ajax_xfor_sendincludes\ajax.php:987
noprivwp_ajax_xfor_sendincludes\ajax.php:988
authwp_ajax_xfor_getincludes\ajax.php:1078
noprivwp_ajax_xfor_getincludes\ajax.php:1079

Shortcodes 1

[hotel_booking] public\init.php:16
WordPress Hooks 8
actionadmin_enqueue_scriptsbackend\init.php:41
filteradmin_footer_textbackend\init.php:46
filterupdate_footerbackend\init.php:47
actionadmin_initbackend\init.php:50
actionplugins_loadedbackend\init.php:58
actionadmin_menubackend\init.php:74
filterwidget_textpublic\init.php:8
actionwp_headpublic\init.php:45
Maintenance & Trust

Hotel Booking by Xfor Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedFeb 8, 2022
PHP min version7.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Hotel Booking by Xfor Developer Profile

utz0r2

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Hotel Booking by Xfor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/hotel-booking-by-xfor/assets/backend.css/wp-content/plugins/hotel-booking-by-xfor/assets/backend.js/wp-content/plugins/hotel-booking-by-xfor/assets/public.css/wp-content/plugins/hotel-booking-by-xfor/assets/public.js/wp-content/plugins/hotel-booking-by-xfor/assets/libs/vue.js/wp-content/plugins/hotel-booking-by-xfor/assets/libs/vue-router.min.js/wp-content/plugins/hotel-booking-by-xfor/assets/libs/vueInputTag.umd.min.js/wp-content/plugins/hotel-booking-by-xfor/assets/libs/axios.min.js+20 more
Script Paths
/wp-content/plugins/hotel-booking-by-xfor/assets/backend.js/wp-content/plugins/hotel-booking-by-xfor/assets/public.js

HTML / DOM Fingerprints

CSS Classes
hotel-booking-wrapper
HTML Comments
=====================================================@author Hotel Booking by Xfor.top=====================================================
Data Attributes
v-modelv-forv-ifv-bindv-onref+2 more
JS Globals
window.hotel_booking_by_xforwindow.ajaxurl
Shortcode Output
[hotel_booking]
FAQ

Frequently Asked Questions about Hotel Booking by Xfor