
Oganro: Hotels, Flights, Transfers, Car Hire, Excursion Search Box Security & Risk Analysis
wordpress.org/plugins/oganro-travel-online-booking-systemTravel portal search box, customisable plugin to create search and book travel website with Hotels, Flights, Car Hire, Transfer and Excursions.
Is Oganro: Hotels, Flights, Transfers, Car Hire, Excursion Search Box Safe to Use in 2026?
Generally Safe
Score 85/100Oganro: Hotels, Flights, Transfers, Car Hire, Excursion Search Box has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The oganro-travel-online-booking-system plugin v1.0 exhibits a mixed security posture. On the positive side, it has a very small attack surface with no direct AJAX or REST API entry points requiring authentication. Furthermore, all detected SQL queries are properly prepared, indicating good practice in database interaction. There are no known CVEs associated with this plugin, suggesting a history of stability or limited public scrutiny.
However, significant concerns arise from the static code analysis. The presence of the `unserialize` function, especially without accompanying nonce or capability checks, represents a critical vulnerability. The fact that 100% of outputs are not properly escaped is another major red flag, opening the door to Cross-Site Scripting (XSS) attacks. The taint analysis revealing two flows with unsanitized paths further exacerbates these risks, suggesting that data entering the plugin might not be adequately validated before being processed or outputted. The lack of nonce checks and capability checks on the identified shortcode entry point is also a significant weakness.
In conclusion, while the plugin benefits from a limited attack surface and secure SQL practices, the high percentage of unescaped output, the dangerous use of `unserialize` without proper checks, and the identified unsanitized taint flows represent substantial security risks that could lead to XSS and potentially Remote Code Execution (RCE) vulnerabilities. The absence of any recorded vulnerabilities could be due to its limited functionality, obscurity, or simply that these vulnerabilities have not yet been discovered or exploited.
Key Concerns
- Dangerous function unserialize without checks
- 0% of outputs properly escaped
- Taint analysis shows unsanitized paths
- No nonce checks
- No capability checks
Oganro: Hotels, Flights, Transfers, Car Hire, Excursion Search Box Security Vulnerabilities
Oganro: Hotels, Flights, Transfers, Car Hire, Excursion Search Box Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Oganro: Hotels, Flights, Transfers, Car Hire, Excursion Search Box Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Oganro: Hotels, Flights, Transfers, Car Hire, Excursion Search Box Maintenance & Trust
Maintenance Signals
Community Trust
Oganro: Hotels, Flights, Transfers, Car Hire, Excursion Search Box Alternatives
XML Travel Portal Widget
oganro-reservation-widget
WordPress Widget which connect to wholesalers/suppliers or GDS through XML APIs to power B2B or B2C travel websites.
Oganro Travel Portal Search Widget for HotelBeds APITUDE API
oganro-travel-portal-search-widget-for-hotelbeds-apitude-api
Oganro HotelBeds search widget will enable for you to build a Wordpress based travel portal website or OTA website without having to worry about all X …
Meta for WooCommerce
facebook-for-woocommerce
Get the Official Meta for WooCommerce plugin for powerful ways to help grow your business.
PixelYourSite – Your smart PIXEL (TAG) & API Manager
pixelyoursite
Add Meta Pixel with Conversion API, Google Analytics (GA4) + Consent Mode, Google Tag Manager, and Head & Footer scripts.
Meta pixel for WordPress
official-facebook-pixel
Grow your business with Meta for WordPress!
Oganro: Hotels, Flights, Transfers, Car Hire, Excursion Search Box Developer Profile
8 plugins · 190 total installs
How We Detect Oganro: Hotels, Flights, Transfers, Car Hire, Excursion Search Box
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oganro-travel-online-booking-system/css/bootstrap.css/wp-content/plugins/oganro-travel-online-booking-system/css/og-travel-widget.css/wp-content/plugins/oganro-travel-online-booking-system/css/bootstrap-datepicker/bootstrap-datepicker.min.css/wp-content/plugins/oganro-travel-online-booking-system/css/font-awesome/css/font-awesome.min.css/wp-content/plugins/oganro-travel-online-booking-system/js/jq-validation/jquery.validate.min.js/wp-content/plugins/oganro-travel-online-booking-system/js/bootstrap.js/wp-content/plugins/oganro-travel-online-booking-system/js/bootstrap-datepicker.min.js/wp-content/plugins/oganro-travel-online-booking-system/js/og-travel-widget.js+3 more/wp-content/plugins/oganro-travel-online-booking-system/js/jq-validation/jquery.validate.min.js/wp-content/plugins/oganro-travel-online-booking-system/js/bootstrap.js/wp-content/plugins/oganro-travel-online-booking-system/js/bootstrap-datepicker.min.js/wp-content/plugins/oganro-travel-online-booking-system/js/og-travel-widget.js/wp-content/plugins/oganro-travel-online-booking-system/js/jqColorPicker/jqColorPicker.min.js/wp-content/plugins/oganro-travel-online-booking-system/js/og-travel.jsHTML / DOM Fingerprints
og-travel-widget-wrapdata-toggledata-targetdata-keyboarddata-backdropdata-controls-modalog_travel_data[og_travel_widget]