
iLabs Booking WooCommerce – apartments, boats, cars Security & Risk Analysis
wordpress.org/plugins/inspirelabs-bookingsThis plugin in integration with Woocommerce allows you to create different products for rent, with the output of the calendar for booking on the produ …
Is iLabs Booking WooCommerce – apartments, boats, cars Safe to Use in 2026?
Generally Safe
Score 85/100iLabs Booking WooCommerce – apartments, boats, cars has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "inspirelabs-bookings" plugin v1.0.2 demonstrates a generally good security posture with several positive indicators. The complete absence of known CVEs, along with a strong reliance on prepared statements for all SQL queries and a high percentage of properly escaped output, suggests a proactive approach to security by the developers. The lack of external HTTP requests and no identified critical or high severity taint flows further bolster this assessment.
However, there are notable areas of concern that elevate the risk. The presence of two AJAX handlers without authentication checks represents a significant attack surface that could be exploited by unauthenticated users to trigger unintended actions. While the plugin has a clean vulnerability history, this could be due to a lack of past audits or a recent development. The absence of capability checks on any entry points is also a critical oversight, as it means WordPress's role-based access control is not being leveraged to protect sensitive operations.
In conclusion, while the plugin shows strengths in its coding practices regarding data handling and query security, the unprotected AJAX endpoints and lack of capability checks introduce significant vulnerabilities. These weaknesses, if exploited, could lead to unauthorized actions or data manipulation. It is recommended that developers address these specific entry points with appropriate authentication and authorization checks.
Key Concerns
- AJAX handlers without auth checks
- No capability checks on entry points
iLabs Booking WooCommerce – apartments, boats, cars Security Vulnerabilities
iLabs Booking WooCommerce – apartments, boats, cars Code Analysis
SQL Query Safety
Output Escaping
iLabs Booking WooCommerce – apartments, boats, cars Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 38
Maintenance & Trust
iLabs Booking WooCommerce – apartments, boats, cars Maintenance & Trust
Maintenance Signals
Community Trust
iLabs Booking WooCommerce – apartments, boats, cars Alternatives
WP Events Manager
wp-events-manager
The all in one Events Manager for WordPress: create and manage events, sell event tickets online easily. No Coding Required.
VikRentCar Car Rental Management System
vikrentcar
Robust Car Rental Management System for any kind of vechicles. The most reliable booking solution for managing vehicles rentals through your website.
Tourfic – Travel Booking, Hotel Booking & Car Rental WordPress Plugin
tourfic
Hotel, Travel, Car Rental & Tour Booking WordPress plugin. Build a website like Agoda, Booking.com, Airbnb, Enterprise, Avis with WooCommerce
WP Events Manager WooCommerce
wp-events-manager-woocommerce-payment-methods-integration
WP Events Manager Woocommerce Plugin - Support paying for booking of WP Events Manager plugin with the payment system provided by WooCommerce.
SeatReg
seatreg
Create and manage online registrations. Design your own registration layout and manage bookings.
iLabs Booking WooCommerce – apartments, boats, cars Developer Profile
7 plugins · 17K total installs
How We Detect iLabs Booking WooCommerce – apartments, boats, cars
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/inspirelabs-bookings/assets/css/inspirelabs-booking-admin.css/wp-content/plugins/inspirelabs-bookings/assets/js/datepicker.min.js/wp-content/plugins/inspirelabs-bookings/assets/js/HelperSettingsIlabsBooking.js/wp-content/plugins/inspirelabs-bookings/assets/js/ProductSettingsIlabsBooking.js/wp-content/plugins/inspirelabs-bookings/vendor_prefixed/wpdesk/wp-plugin-flow/src/plugin-init-php52-free.phpinspirelabs-bookings/assets/css/inspirelabs-booking-admin.css?ver=inspirelabs-bookings/assets/js/datepicker.min.js?ver=inspirelabs-bookings/assets/js/HelperSettingsIlabsBooking.js?ver=inspirelabs-bookings/assets/js/ProductSettingsIlabsBooking.js?ver=HTML / DOM Fingerprints
hide_if_bookingshow_if_bookingprice_l/wp-json/inspirelabs-bookings/v1/get-pricelist