
Visitor Check-In/Check-Out Logbook – WordPress Visitor Management Security & Risk Analysis
wordpress.org/plugins/office-visits-logbookYour company is still using paper log sheets for office visitors? Everything is digital and paperless now. Being paperless can also save trees and pro …
Is Visitor Check-In/Check-Out Logbook – WordPress Visitor Management Safe to Use in 2026?
Generally Safe
Score 100/100Visitor Check-In/Check-Out Logbook – WordPress Visitor Management has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "office-visits-logbook" v1.1.3 plugin exhibits a generally strong security posture, particularly in its handling of user input and output. The plugin demonstrates a commendable use of prepared statements for SQL queries (64%) and proper output escaping (83%), significantly reducing the risk of common web vulnerabilities like SQL injection and cross-site scripting. The absence of known CVEs and a clean vulnerability history further reinforce this positive assessment. However, a few areas warrant attention. The presence of 4 flows with unsanitized paths in the taint analysis, and one of high severity, indicates a potential risk for directory traversal or file inclusion vulnerabilities, which could be exploited if these paths are user-controlled. Additionally, the large number of AJAX handlers (17) combined with a complete lack of capability checks, while present nonce checks, suggests a potential weakness. While nonce checks are important for preventing CSRF, they do not prevent unauthorized access if an attacker can trick a logged-in user with insufficient privileges to trigger an AJAX action. The plugin's strengths lie in its robust data handling, but the identified taint flows and the complete absence of capability checks on its extensive AJAX endpoints are notable weaknesses.
Key Concerns
- High severity unsanitized path in taint flow
- 4 unsanitized paths in taint flow
- No capability checks on 17 AJAX handlers
Visitor Check-In/Check-Out Logbook – WordPress Visitor Management Security Vulnerabilities
Visitor Check-In/Check-Out Logbook – WordPress Visitor Management Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Visitor Check-In/Check-Out Logbook – WordPress Visitor Management Attack Surface
AJAX Handlers 17
WordPress Hooks 6
Maintenance & Trust
Visitor Check-In/Check-Out Logbook – WordPress Visitor Management Maintenance & Trust
Maintenance Signals
Community Trust
Visitor Check-In/Check-Out Logbook – WordPress Visitor Management Alternatives
WPS Visitor Counter
wps-visitor-counter
Display website visitor statistics with widget, shortcode, and Gutenberg block support.
Mechanic Visitor Counter
mechanic-visitor-counter
Mechanic Visitor Counter is a widgets which will display the Visitor counter and traffic statistics on WordPress. Some of the features offered include …
XT Visitor Counter
xt-visitor-counter
XT Visitor Counter is a widgets which will display the Visitor counter and traffic statistics on WordPress. Some of the features offered include Today …
IP Informant Logger
ip-informant-logger
Logs and displays visitor IP addresses for website security and monitoring.
Blog Demographics
blog-demographics
Shows you what age and gender your visitors are. Based on various services like Facebook, BlogCatalog and MyBlogLog.
Visitor Check-In/Check-Out Logbook – WordPress Visitor Management Developer Profile
4 plugins · 10 total installs
How We Detect Visitor Check-In/Check-Out Logbook – WordPress Visitor Management
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/office-visits-logbook/css/normalize.css/wp-content/plugins/office-visits-logbook/css/style.css/wp-content/plugins/office-visits-logbook/js/script.js/wp-content/plugins/office-visits-logbook/js/jquery-ui.js/wp-content/plugins/office-visits-logbook/js/datepicker-en.jsoffice-visits-logbook/css/normalize.css?ver=office-visits-logbook/css/style.css?ver=office-visits-logbook/js/script.js?ver=office-visits-logbook/js/jquery-ui.js?ver=office-visits-logbook/js/datepicker-en.js?ver=HTML / DOM Fingerprints
office-visits-logbook-entry-formoffice-visits-logbook-visitor-listoffice-visits-logbook-admin-menudata-plugin="office-visits-logbook"officeVisitsLogbookdragonvisitzyx987_params/wp-json/office-visits-logbook/v1/entries[office_visits_logbook_form][office_visits_logbook_list]