Yoga Schedule Momoyoga Security & Risk Analysis

wordpress.org/plugins/momoyoga-integration

Show your Momoyoga class schedule on your WordPress website.

1K active installs v2.9.1 PHP + WP 4.0+ Updated Mar 4, 2026
bookingscalendarmomoyogascheduleyoga
98
A · Safe
CVEs total2
Unpatched0
Last CVESep 29, 2025
Safety Verdict

Is Yoga Schedule Momoyoga Safe to Use in 2026?

Generally Safe

Score 98/100

Yoga Schedule Momoyoga has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Sep 29, 2025Updated 1mo ago
Risk Assessment

The momoyoga-integration plugin v2.9.1 exhibits a generally good security posture regarding its immediate code. The static analysis reveals no dangerous functions, all SQL queries are prepared, and all output is properly escaped. Furthermore, there are no observed file operations, external HTTP requests, or untrusted taint flows, indicating a diligent approach to preventing common injection vulnerabilities. The limited attack surface, with only one shortcode and no unprotected AJAX handlers or REST API routes, is a positive sign.

However, a significant concern arises from its vulnerability history. The plugin has two known CVEs, both of medium severity, and historically suffers from Cross-site Scripting (XSS) vulnerabilities. While none are currently unpatched, the recurrence of XSS suggests potential weaknesses in how user input is handled in certain contexts that might not have been fully captured by the static analysis, or perhaps a pattern of past vulnerabilities that could resurface. The lack of nonce checks and capability checks, while not immediately exploitable given the static analysis results, could be an oversight that might become problematic if the plugin's functionality or attack surface evolves.

In conclusion, the plugin demonstrates strengths in fundamental secure coding practices. The code itself appears robust against many common attack vectors. The primary area of concern is the historical presence of XSS vulnerabilities, which warrants careful monitoring and a thorough understanding of how all user-provided data is ultimately rendered. The absence of nonce and capability checks on entry points, though currently not leading to identified vulnerabilities, represents a potential gap in defense-in-depth.

Key Concerns

  • Known CVEs in vulnerability history
  • Lack of nonce checks
  • Lack of capability checks
Vulnerabilities
2

Yoga Schedule Momoyoga Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-9852medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Yoga Schedule Momoyoga <= 2.9.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Sep 29, 2025 Patched in 2.9.1 (22d)
CVE-2024-32529medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Yoga Schedule Momoyoga <= 2.7.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 15, 2024 Patched in 2.8.0 (19d)
Code Analysis
Analyzed Mar 16, 2026

Yoga Schedule Momoyoga Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
5 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

100% escaped5 total outputs
Attack Surface

Yoga Schedule Momoyoga Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[momoyoga-schedule] momoyoga-schedule.php:28
WordPress Hooks 8
filtermce_external_pluginsmomoyoga-admin.php:14
filtermce_buttonsmomoyoga-admin.php:15
actionadmin_noticesmomoyoga-admin.php:17
actionmedia_buttonsmomoyoga-admin.php:18
actionadmin_print_footer_scriptsmomoyoga-admin.php:50
actioninitmomoyoga-schedule.php:63
actioninitmomoyoga-schedule.php:67
actioninitmomoyoga-schedule.php:71
Maintenance & Trust

Yoga Schedule Momoyoga Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version
Downloads25K

Community Trust

Rating100/100
Number of ratings2
Active installs1K
Developer Profile

Yoga Schedule Momoyoga Developer Profile

Stefan | Momoyoga

1 plugin · 1K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
21 days
View full developer profile
Detection Fingerprints

How We Detect Yoga Schedule Momoyoga

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/momoyoga-integration/css/schedule-frontend.min.css/wp-content/plugins/momoyoga-integration/css/admin.css/wp-content/plugins/momoyoga-integration/js/tinymce-plugin-schedule-button.js/wp-content/plugins/momoyoga-integration/js/editor-view.js/wp-content/plugins/momoyoga-integration/css/editor-inline-editing-style.css/wp-content/plugins/momoyoga-integration/css/editor-style.css
Script Paths
/wp-content/plugins/momoyoga-integration/js/schedule.min.js
Version Parameters
momoyoga-integration/css/editor-inline-editing-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
momoyoga-schedulemomoyoga-schedule-icon
Data Attributes
data-momo-schedule
JS Globals
momoyogaScheduleEditorView
Shortcode Output
<div class="momoyoga-schedule"><button id="insert-momoyoga-schedule" class="button" title="
FAQ

Frequently Asked Questions about Yoga Schedule Momoyoga