Mobile-Refuel Table Reservation Security & Risk Analysis

wordpress.org/plugins/mobile-refuel-table-reservation

Professional table reservation system for restaurants. Manage bookings, opening hours, and guest communication via your personal app.

0 active installs v1.2.6 PHP 7.4+ WP + Updated Mar 13, 2026
reservationrestaurantrestaurant-bookingrestaurant-reservationstable-reservation
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Mobile-Refuel Table Reservation Safe to Use in 2026?

Generally Safe

Score 100/100

Mobile-Refuel Table Reservation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 21d ago
Risk Assessment

The mobile-refuel-table-reservation plugin v1.2.6 exhibits a generally good security posture with several strengths. The vast majority of SQL queries utilize prepared statements, and an impressive 93% of outputs are properly escaped, significantly mitigating common injection and cross-site scripting vulnerabilities. The plugin also demonstrates a strong adherence to WordPress security best practices by including a substantial number of nonce checks and at least one capability check.

However, there are notable areas of concern. The presence of two AJAX handlers without authentication checks represents a significant attack surface that could potentially be exploited by unauthenticated users. Furthermore, the taint analysis revealed four flows with unsanitized paths, all classified as high severity. This indicates potential vulnerabilities where user-supplied data could be improperly processed, leading to security issues like directory traversal or command injection.

The plugin's vulnerability history is currently clean, with no recorded CVEs. This is a positive indicator, suggesting the developers have a good track record. Nevertheless, the identified weaknesses in the static and taint analysis, particularly the unprotected AJAX endpoints and high-severity unsanitized paths, warrant immediate attention to prevent potential exploitation.

Key Concerns

  • Unprotected AJAX handlers found
  • High severity unsanitized taint flows found
Vulnerabilities
None known

Mobile-Refuel Table Reservation Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Mobile-Refuel Table Reservation Code Analysis

Dangerous Functions
0
Raw SQL Queries
7
16 prepared
Unescaped Output
44
580 escaped
Nonce Checks
20
Capability Checks
1
File Operations
15
External Requests
0
Bundled Libraries
0

SQL Query Safety

70% prepared23 total queries

Output Escaping

93% escaped624 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

11 flows4 with unsanitized paths
<einstellungen> (admin\einstellungen.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Mobile-Refuel Table Reservation Attack Surface

Entry Points14
Unprotected2

AJAX Handlers 13

authwp_ajax_mrtr_speichernmobile-refuel-tischreservierungen.php:878
noprivwp_ajax_mrtr_speichernmobile-refuel-tischreservierungen.php:879
authwp_ajax_mrtr_get_available_timesmobile-refuel-tischreservierungen.php:882
noprivwp_ajax_mrtr_get_available_timesmobile-refuel-tischreservierungen.php:883
authwp_ajax_mrtr_sende_nachricht_an_gastmobile-refuel-tischreservierungen.php:885
authwp_ajax_mrtr_get_email_templatesmobile-refuel-tischreservierungen.php:886
authwp_ajax_mrtr_get_calendar_eventsmobile-refuel-tischreservierungen.php:889
authwp_ajax_mrtr_get_reservierung_detailsmobile-refuel-tischreservierungen.php:890
authwp_ajax_mrtr_generate_calendar_tokenmobile-refuel-tischreservierungen.php:891
authwp_ajax_mrtr_delete_calendar_tokenmobile-refuel-tischreservierungen.php:892
authwp_ajax_mrtr_calendar_feedmobile-refuel-tischreservierungen.php:893
noprivwp_ajax_mrtr_calendar_feedmobile-refuel-tischreservierungen.php:894
authwp_ajax_mrtr_get_action_noncesmobile-refuel-tischreservierungen.php:895

Shortcodes 1

[reservation-form] mobile-refuel-tischreservierungen.php:876
WordPress Hooks 16
actionadmin_menumobile-refuel-tischreservierungen.php:464
actionadmin_initmobile-refuel-tischreservierungen.php:870
actionadmin_menumobile-refuel-tischreservierungen.php:877
actionwp_enqueue_scriptsmobile-refuel-tischreservierungen.php:880
actionadmin_enqueue_scriptsmobile-refuel-tischreservierungen.php:881
filterwp_mail_frommobile-refuel-tischreservierungen.php:897
filterwp_mail_from_namemobile-refuel-tischreservierungen.php:898
actionadmin_initmobile-refuel-tischreservierungen.php:899
actionadmin_initmobile-refuel-tischreservierungen.php:902
actionadmin_initmobile-refuel-tischreservierungen.php:905
actionadmin_initmobile-refuel-tischreservierungen.php:908
actionplugins_loadedmobile-refuel-tischreservierungen.php:911
actioninitmobile-refuel-tischreservierungen.php:912
filterplugin_localemobile-refuel-tischreservierungen.php:913
actioninitmobile-refuel-tischreservierungen.php:916
actionadmin_initmobile-refuel-tischreservierungen.php:2422
Maintenance & Trust

Mobile-Refuel Table Reservation Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 13, 2026
PHP min version7.4
Downloads743

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

Mobile-Refuel Table Reservation Developer Profile

Maxim Ristow

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mobile-Refuel Table Reservation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mobile-refuel-table-reservation/css/style.css/wp-content/plugins/mobile-refuel-table-reservation/css/admin.css/wp-content/plugins/mobile-refuel-table-reservation/js/scripts.js
Script Paths
/wp-content/plugins/mobile-refuel-table-reservation/js/scripts.js
Version Parameters
mobile-refuel-table-reservation/style.css?ver=mobile-refuel-table-reservation/css/admin.css?ver=mobile-refuel-table-reservation/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
mrtr-reservation-formmrtr-reservation-calendarmrtr-reservation-detailsmrtr-admin-section
HTML Comments
<!-- Mobile-Refuel Table Reservation Plugin --><!-- Start: Mobile-Refuel Table Reservation Form --><!-- End: Mobile-Refuel Table Reservation Form --><!-- Start: Mobile-Refuel Admin Settings -->+1 more
Data Attributes
data-restaurant-namedata-reservation-iddata-action='mrtr_save_reservation'data-action='mrtr_delete_reservation'
JS Globals
var mrtr_ajax_object = var mrtr_settings = window.mrtr_booking_data =
REST Endpoints
/wp-json/mobile-refuel-table-reservation/v1/reservations/wp-json/mobile-refuel-table-reservation/v1/settings
Shortcode Output
[mobile_refuel_reservation_form][mobile_refuel_reservation_list][mobile_refuel_availability_calendar]
FAQ

Frequently Asked Questions about Mobile-Refuel Table Reservation