
Yoga Schedule Momoyoga Security & Risk Analysis
wordpress.org/plugins/momoyoga-integrationShow your Momoyoga class schedule on your WordPress website.
Is Yoga Schedule Momoyoga Safe to Use in 2026?
Generally Safe
Score 98/100Yoga Schedule Momoyoga has a strong security track record. Known vulnerabilities have been patched promptly.
The momoyoga-integration plugin v2.9.1 exhibits a generally good security posture regarding its immediate code. The static analysis reveals no dangerous functions, all SQL queries are prepared, and all output is properly escaped. Furthermore, there are no observed file operations, external HTTP requests, or untrusted taint flows, indicating a diligent approach to preventing common injection vulnerabilities. The limited attack surface, with only one shortcode and no unprotected AJAX handlers or REST API routes, is a positive sign.
However, a significant concern arises from its vulnerability history. The plugin has two known CVEs, both of medium severity, and historically suffers from Cross-site Scripting (XSS) vulnerabilities. While none are currently unpatched, the recurrence of XSS suggests potential weaknesses in how user input is handled in certain contexts that might not have been fully captured by the static analysis, or perhaps a pattern of past vulnerabilities that could resurface. The lack of nonce checks and capability checks, while not immediately exploitable given the static analysis results, could be an oversight that might become problematic if the plugin's functionality or attack surface evolves.
In conclusion, the plugin demonstrates strengths in fundamental secure coding practices. The code itself appears robust against many common attack vectors. The primary area of concern is the historical presence of XSS vulnerabilities, which warrants careful monitoring and a thorough understanding of how all user-provided data is ultimately rendered. The absence of nonce and capability checks on entry points, though currently not leading to identified vulnerabilities, represents a potential gap in defense-in-depth.
Key Concerns
- Known CVEs in vulnerability history
- Lack of nonce checks
- Lack of capability checks
Yoga Schedule Momoyoga Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Yoga Schedule Momoyoga <= 2.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Yoga Schedule Momoyoga <= 2.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Yoga Schedule Momoyoga Code Analysis
Bundled Libraries
Output Escaping
Yoga Schedule Momoyoga Attack Surface
Shortcodes 1
WordPress Hooks 8
Maintenance & Trust
Yoga Schedule Momoyoga Maintenance & Trust
Maintenance Signals
Community Trust
Yoga Schedule Momoyoga Alternatives
MZ MBO Access
mindbody-access-management
Restrict wordpress content based on client Mindbody account details. Create two access levels based on MBO membership details.
The Events Calendar
the-events-calendar
The Events Calendar: #1 calendar plugin for WordPress. Create/manage events (virtual too!) on your site with the free plugin.
Events Manager – Calendar, Bookings, Tickets, and more!
events-manager
Events calendar with bookings, scheduling, appointments, event registration, tickets, recurring events, and venue management.
Booking Calendar
booking
Original "Booking Calendar" plugin. Easily manage full-day bookings, time-slot appointments, or events in our all-in-one, outstanding booking system.
Timetable and Event Schedule by MotoPress
mp-timetable
Smart event organizer and time-management tool with a clean minimalist design for featuring your timetables and upcoming events.
Yoga Schedule Momoyoga Developer Profile
1 plugin · 1K total installs
How We Detect Yoga Schedule Momoyoga
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/momoyoga-integration/css/schedule-frontend.min.css/wp-content/plugins/momoyoga-integration/css/admin.css/wp-content/plugins/momoyoga-integration/js/tinymce-plugin-schedule-button.js/wp-content/plugins/momoyoga-integration/js/editor-view.js/wp-content/plugins/momoyoga-integration/css/editor-inline-editing-style.css/wp-content/plugins/momoyoga-integration/css/editor-style.css/wp-content/plugins/momoyoga-integration/js/schedule.min.jsmomoyoga-integration/css/editor-inline-editing-style.css?ver=HTML / DOM Fingerprints
momoyoga-schedulemomoyoga-schedule-icondata-momo-schedulemomoyogaScheduleEditorView<div class="momoyoga-schedule"><button id="insert-momoyoga-schedule" class="button" title="