Oganro Travel Portal Search Widget for HotelBeds APITUDE API Security & Risk Analysis

wordpress.org/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api

Oganro HotelBeds search widget will enable for you to build a Wordpress based travel portal website or OTA website without having to worry about all X …

10 active installs v1.0 PHP + WP 3.9+ Updated Aug 4, 2016
apib2b-travel-portal-widgetb2c-travel-portal-widgetdynamichotelbeds
63
C · Use Caution
CVEs total1
Unpatched1
Last CVEJun 19, 2025
Safety Verdict

Is Oganro Travel Portal Search Widget for HotelBeds APITUDE API Safe to Use in 2026?

Use With Caution

Score 63/100

Oganro Travel Portal Search Widget for HotelBeds APITUDE API has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.

1 known CVE 1 unpatched Last CVE: Jun 19, 2025Updated 9yr ago
Risk Assessment

The overall security posture of the 'oganro-travel-portal-search-widget-for-hotelbeds-apitude-api' plugin v1.0 shows some positive aspects but also presents notable concerns. The static analysis indicates a very small attack surface with only one shortcode, and importantly, no unprotected entry points. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and largely proper output escaping. However, the complete absence of nonce checks is a significant weakness that could expose the plugin to Cross-Site Request Forgery (CSRF) attacks.

Taint analysis revealed no flows with unsanitized paths, which is a strong positive. The plugin also avoids dangerous functions, file operations, and external HTTP requests. The single capability check is present but its effectiveness is limited by the lack of other security mechanisms. The vulnerability history is concerning, with one known medium-severity CVE that remains unpatched. The historical pattern of CSRF vulnerabilities, coupled with the current lack of nonce checks, strongly suggests a recurring weakness that needs immediate attention.

In conclusion, while the plugin adheres to some secure coding principles like prepared statements and output escaping, the absence of nonce checks and the presence of an unpatched medium-severity CVE are critical vulnerabilities. The historical pattern of CSRF issues highlights a systemic problem that significantly lowers its security rating. Addressing the unpatched CVE and implementing proper nonce checks are paramount to improving its security.

Key Concerns

  • Unpatched medium severity CVE
  • Missing nonce checks
Vulnerabilities
1

Oganro Travel Portal Search Widget for HotelBeds APITUDE API Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-49966medium · 4.3Cross-Site Request Forgery (CSRF)

Oganro Travel Portal Search Widget for HotelBeds APITUDE API <= 1.0 - Cross-Site Request Forgery

Jun 19, 2025Unpatched
Code Analysis
Analyzed Mar 17, 2026

Oganro Travel Portal Search Widget for HotelBeds APITUDE API Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
200 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

99% escaped202 total outputs
Attack Surface

Oganro Travel Portal Search Widget for HotelBeds APITUDE API Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ogn-hxsw-travel-portal-search-box] ogn-hxsw-hotelbeds-xml-search-widget.php:31
WordPress Hooks 1
actionadmin_menuogn-hxsw-hotelbeds-xml-search-widget.php:50
Maintenance & Trust

Oganro Travel Portal Search Widget for HotelBeds APITUDE API Maintenance & Trust

Maintenance Signals

WordPress version tested4.8.28
Last updatedAug 4, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Oganro Travel Portal Search Widget for HotelBeds APITUDE API Developer Profile

Oganro

8 plugins · 190 total installs

81
trust score
Avg Security Score
81/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Oganro Travel Portal Search Widget for HotelBeds APITUDE API

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/css/ogn_hxsw_jquery_ui.css/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/css/ogn_hxsw_bootstrap_min.css/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/css/ogn_hxsw_reservation_admin.css/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/css/ogn_hxsw_tinytools_toggleswitch_min.css/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_bootstrap_min.js/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_sb_script.js/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_jscolor.js/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_tinytools_toggleswitch_min.js+1 more
Script Paths
/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_bootstrap_min.js/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_sb_script.js/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_jscolor.js/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_tinytools_toggleswitch_min.js/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_admin_sb_script.js

HTML / DOM Fingerprints

CSS Classes
ogn_hxsw_search_box_wrapperogn_hxsw_search_boxogn_hxsw_search_inputogn_hxsw_date_inputogn_hxsw_nights_inputogn_hxsw_rooms_inputogn_hxsw_search_buttonogn_hxsw_admin_form+1 more
HTML Comments
Installation InstructionsInitiating Methods to generate Search boxInitiating action to add search box admin menuadd search box admin menu+3 more
Data Attributes
data-plugin-name="oganro-travel-portal-search-widget-for-hotelbeds-apitude-api"data-plugin-version="1.0"
JS Globals
ogn_hxsw_bootstrap
Shortcode Output
[ogn-hxsw-travel-portal-search-box]
FAQ

Frequently Asked Questions about Oganro Travel Portal Search Widget for HotelBeds APITUDE API