Molzait Widget Security & Risk Analysis

wordpress.org/plugins/molzait-widget

Regain command of your reservation process with Molzait.

40 active installs v1.2.0 PHP + WP + Updated Unknown
bookingsmolzaitreservation-systemreservationsrestaurant
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Molzait Widget Safe to Use in 2026?

Generally Safe

Score 100/100

Molzait Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

Based on the static analysis, the "molzait-widget" v1.2.0 plugin appears to have a strong security posture regarding common web vulnerabilities. The absence of AJAX handlers, REST API routes, shortcodes, cron events, and dangerous functions indicates a very limited attack surface and a lack of obvious entry points for exploitation. Furthermore, all SQL queries utilize prepared statements, and there are no file operations or external HTTP requests, all of which are excellent security practices.

The plugin also shows good adherence to output escaping, with 75% of outputs being properly escaped, although the remaining 25% might represent a minor area of concern depending on the context of those outputs. The lack of taint analysis results and critical/high severity flows is reassuring, suggesting no immediate critical security flaws were detected.

With no recorded CVEs and no history of vulnerabilities, this plugin has demonstrated a clean track record. However, the complete absence of nonce checks and capability checks across all identified code signals is a significant weakness. While the current lack of entry points is beneficial, if any are introduced in future versions or if an indirect vulnerability is discovered that allows access to the plugin's functionality, these missing checks could become critical.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Unescaped output (25% of 8)
Vulnerabilities
None known

Molzait Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Molzait Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
6 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped8 total outputs
Attack Surface

Molzait Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menumolzait-widget.php:17
actionadmin_initmolzait-widget.php:48
actionwp_headmolzait-widget.php:88
Maintenance & Trust

Molzait Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Molzait Widget Developer Profile

molzait

1 plugin · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Molzait Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
https://reserve.molzait.com/assets/embed.js

HTML / DOM Fingerprints

Data Attributes
molzaitdata-restaurant-idsdata-open-selectorsdata-initial-colordata-hide-button
FAQ

Frequently Asked Questions about Molzait Widget