
Oganro Travel Portal Search Widget for HotelBeds APITUDE API Security & Risk Analysis
wordpress.org/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-apiOganro HotelBeds search widget will enable for you to build a Wordpress based travel portal website or OTA website without having to worry about all X …
Is Oganro Travel Portal Search Widget for HotelBeds APITUDE API Safe to Use in 2026?
Use With Caution
Score 63/100Oganro Travel Portal Search Widget for HotelBeds APITUDE API has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The overall security posture of the 'oganro-travel-portal-search-widget-for-hotelbeds-apitude-api' plugin v1.0 shows some positive aspects but also presents notable concerns. The static analysis indicates a very small attack surface with only one shortcode, and importantly, no unprotected entry points. The code also demonstrates good practices by utilizing prepared statements for all SQL queries and largely proper output escaping. However, the complete absence of nonce checks is a significant weakness that could expose the plugin to Cross-Site Request Forgery (CSRF) attacks.
Taint analysis revealed no flows with unsanitized paths, which is a strong positive. The plugin also avoids dangerous functions, file operations, and external HTTP requests. The single capability check is present but its effectiveness is limited by the lack of other security mechanisms. The vulnerability history is concerning, with one known medium-severity CVE that remains unpatched. The historical pattern of CSRF vulnerabilities, coupled with the current lack of nonce checks, strongly suggests a recurring weakness that needs immediate attention.
In conclusion, while the plugin adheres to some secure coding principles like prepared statements and output escaping, the absence of nonce checks and the presence of an unpatched medium-severity CVE are critical vulnerabilities. The historical pattern of CSRF issues highlights a systemic problem that significantly lowers its security rating. Addressing the unpatched CVE and implementing proper nonce checks are paramount to improving its security.
Key Concerns
- Unpatched medium severity CVE
- Missing nonce checks
Oganro Travel Portal Search Widget for HotelBeds APITUDE API Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Oganro Travel Portal Search Widget for HotelBeds APITUDE API <= 1.0 - Cross-Site Request Forgery
Oganro Travel Portal Search Widget for HotelBeds APITUDE API Code Analysis
Output Escaping
Oganro Travel Portal Search Widget for HotelBeds APITUDE API Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Oganro Travel Portal Search Widget for HotelBeds APITUDE API Maintenance & Trust
Maintenance Signals
Community Trust
Oganro Travel Portal Search Widget for HotelBeds APITUDE API Alternatives
XML Travel Portal Widget
oganro-reservation-widget
WordPress Widget which connect to wholesalers/suppliers or GDS through XML APIs to power B2B or B2C travel websites.
Pixel Tag Manager for WooCommerce – Google Analytics 4, Google Ads, and More Pixels
pixel-manager-for-woocommerce
Pixel Tag Manager for WooCommerce is a powerful plugin to monitor eCommerce events with seamless integration. Track Google Analytics 4, Google Ads, Bi …
Oganro: Hotels, Flights, Transfers, Car Hire, Excursion Search Box
oganro-travel-online-booking-system
Travel portal search box, customisable plugin to create search and book travel website with Hotels, Flights, Car Hire, Transfer and Excursions.
Meta for WooCommerce
facebook-for-woocommerce
Get the Official Meta for WooCommerce plugin for powerful ways to help grow your business.
PixelYourSite – Your smart PIXEL (TAG) & API Manager
pixelyoursite
Add Meta Pixel with Conversion API, Google Analytics (GA4) + Consent Mode, Google Tag Manager, and Head & Footer scripts.
Oganro Travel Portal Search Widget for HotelBeds APITUDE API Developer Profile
8 plugins · 190 total installs
How We Detect Oganro Travel Portal Search Widget for HotelBeds APITUDE API
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/css/ogn_hxsw_jquery_ui.css/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/css/ogn_hxsw_bootstrap_min.css/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/css/ogn_hxsw_reservation_admin.css/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/css/ogn_hxsw_tinytools_toggleswitch_min.css/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_bootstrap_min.js/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_sb_script.js/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_jscolor.js/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_tinytools_toggleswitch_min.js+1 more/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_bootstrap_min.js/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_sb_script.js/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_jscolor.js/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_tinytools_toggleswitch_min.js/wp-content/plugins/oganro-travel-portal-search-widget-for-hotelbeds-apitude-api/js/ogn_hxsw_admin_sb_script.jsHTML / DOM Fingerprints
ogn_hxsw_search_box_wrapperogn_hxsw_search_boxogn_hxsw_search_inputogn_hxsw_date_inputogn_hxsw_nights_inputogn_hxsw_rooms_inputogn_hxsw_search_buttonogn_hxsw_admin_form+1 moreInstallation InstructionsInitiating Methods to generate Search boxInitiating action to add search box admin menuadd search box admin menu+3 moredata-plugin-name="oganro-travel-portal-search-widget-for-hotelbeds-apitude-api"data-plugin-version="1.0"ogn_hxsw_bootstrap[ogn-hxsw-travel-portal-search-box]