
Booking System Calendar Security & Risk Analysis
wordpress.org/plugins/kenzap-calendarDisplay calendar section for appointments reservations or bookings. Specify custom time slots. Link checkout process with WooCommerce.
Is Booking System Calendar Safe to Use in 2026?
Generally Safe
Score 85/100Booking System Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The kenzap-calendar plugin v1.0.6 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries, performing a reasonable number of capability checks, and avoiding dangerous functions and file operations. The absence of known CVEs and bundled libraries is also encouraging, suggesting a relatively clean history and development approach.
However, a significant concern arises from the presence of four AJAX handlers that lack authentication checks. This creates a substantial attack surface, as any unauthenticated user could potentially interact with these endpoints, leading to unintended actions. While the taint analysis did not reveal critical or high-severity unsanitized paths, the fact that all four analyzed flows had unsanitized paths is a red flag, even if they didn't escalate to critical levels in this specific analysis. The 80% output escaping rate, while good, also means 20% of outputs are not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if those unescaped outputs are user-controllable.
Overall, the plugin has strengths in its SQL handling and lack of historical vulnerabilities. However, the unprotected AJAX endpoints and the presence of unsanitized flows within the taint analysis present a clear and immediate risk. Addressing these unprotected entry points should be a priority to improve the plugin's security.
Key Concerns
- 4 AJAX handlers without auth checks
- 4 unsanitized paths in taint flows
- 20% of outputs not properly escaped
Booking System Calendar Security Vulnerabilities
Booking System Calendar Release Timeline
Booking System Calendar Code Analysis
Output Escaping
Data Flow Analysis
Booking System Calendar Attack Surface
AJAX Handlers 4
WordPress Hooks 39
Maintenance & Trust
Booking System Calendar Maintenance & Trust
Maintenance Signals
Community Trust
Booking System Calendar Alternatives
Booking calendar, Appointment Booking System
booking-calendar
Booking calendar plugin is an awesome tool for creating appointment booking calendars and Scheduling systems in a few minutes.
Online Scheduling and Appointment Booking System – Bookly
bookly-responsive-appointment-booking-tool
Appointment booking system for WordPress — schedule appointments, manage calendars, send reminders, take payments. Start booking today!
WP Booking System – Booking Calendar
wp-booking-system
The booking calendar plugin for WordPress. Get easy online booking with this lightweight and powerful booking calendar.
Easy Appointment Booking & Scheduling System – Webba Booking Calendar
webba-booking-lite
Free Appointment Booking Plugin 📅 Unlimited appointments, booking management, calendar sync, notifications, 5* support = powerful booking system!
Timetics – Appointment Booking & Scheduling
timetics
Appointment booking and scheduling system with online booking calendar, payments, automated reminders, and calendar sync.
Booking System Calendar Developer Profile
10 plugins · 300 total installs
How We Detect Booking System Calendar
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/kenzap-calendar/css/kenzap-calendar.css/wp-content/plugins/kenzap-calendar/js/kenzap-calendar.js/wp-content/plugins/kenzap-calendar/js/jquery.min.js/wp-content/plugins/kenzap-calendar/js/jquery-ui.min.js/wp-content/plugins/kenzap-calendar/css/jquery-ui.min.css/wp-content/plugins/kenzap-calendar/js/kenzap-calendar.js/wp-content/plugins/kenzap-calendar/js/jquery.min.js/wp-content/plugins/kenzap-calendar/js/jquery-ui.min.jskenzap-calendar/css/kenzap-calendar.css?ver=kenzap-calendar/js/kenzap-calendar.js?ver=kenzap-calendar/js/jquery.min.js?ver=kenzap-calendar/js/jquery-ui.min.js?ver=kenzap-calendar/css/jquery-ui.min.css?ver=HTML / DOM Fingerprints
kenzap-calendar-wrapperkenzap-calendar-containerkenzap-calendar-event-listkenzap-calendar-event-itemdata-kenzap-calendar-idKenzapCalendar[kenzap_calendar]