
eZee Online Hotel Booking Engine Security & Risk Analysis
wordpress.org/plugins/online-booking-engineeZee Reservation plugin is solutions for hotel, resorts, B&B, hotel chains, to get commission free online bookings from their own hotel website.
Is eZee Online Hotel Booking Engine Safe to Use in 2026?
Use With Caution
Score 63/100eZee Online Hotel Booking Engine has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "online-booking-engine" plugin version 1.0.0 presents a mixed security posture. While the static analysis shows a minimal attack surface with no unprotected entry points, zero dangerous functions, and all SQL queries using prepared statements, several significant concerns are present. Notably, 100% of the identified output operations are not properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of nonce checks and capability checks across its entry points further exacerbates this risk, as these are fundamental security mechanisms for WordPress plugins.
The vulnerability history reveals a concerning pattern. There is one known medium severity CVE related to Cross-Site Scripting, which is currently unpatched. The fact that the last vulnerability was dated in the future (2025-09-22) suggests a potential reporting anomaly or a proactive security disclosure, but the existence of an unpatched medium vulnerability in a past version is a significant red flag. The combination of unescaped output and a known XSS vulnerability points to a high likelihood of successful XSS attacks, especially given the lack of robust input validation or authorization checks on its single shortcode entry point.
In conclusion, despite some positive static analysis findings like prepared SQL statements and a small attack surface, the plugin's security is significantly undermined by its failure to escape output and its history of unpatched vulnerabilities, particularly XSS. These weaknesses, coupled with the lack of nonce and capability checks, create a considerable risk for sites utilizing this plugin.
Key Concerns
- Unpatched CVE exists
- Output is not properly escaped
- No nonce checks found
- No capability checks found
eZee Online Hotel Booking Engine Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
eZee Online Hotel Booking Engine <= 1.0.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
eZee Online Hotel Booking Engine Code Analysis
Output Escaping
eZee Online Hotel Booking Engine Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
eZee Online Hotel Booking Engine Maintenance & Trust
Maintenance Signals
Community Trust
eZee Online Hotel Booking Engine Alternatives
BookServe Online Booking Calendar
book-serve-reservations
Makes a calendar and booking form widget to take the user to the Book Serve Hotel Booking Engine.
WP Booking System – Booking Calendar
wp-booking-system
The booking calendar plugin for WordPress. Get easy online booking with this lightweight and powerful booking calendar.
Pinpoint Booking System – Version 2
booking-system
Book anything, anytime, anywhere.
Booqable Rental Plugin
booqable-rental-reservations
Booqable - WordPress Rental Plugin
Twice Commerce – Easy Rental Booking System
embed-rentle
Free rental and booking plugin for Wordpress websites by Twice Commerce. Reservations with real-time inventory availability for rentals and activity s …
eZee Online Hotel Booking Engine Developer Profile
1 plugin · 100 total installs
How We Detect eZee Online Hotel Booking Engine
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/online-booking-engine/css/ezee.css/wp-content/plugins/online-booking-engine/js/ezee-res.jsonline-booking-engine-script?ver=1.0HTML / DOM Fingerprints
ezeesettingfrmcodeinfoeditframename="editframe"id="editframe"class="editframe"window.ezeebe_add_front_script<iframe src="https://live.ipms247.com/booking/book-rooms-name="editframe"class="editframe"id="editframe"