Online Pre-Travel Shopping Security & Risk Analysis

wordpress.org/plugins/online-pre-travel-shopping

shopnfly is the first ever online, pre-travel shopping experience, creating a one-stop-shop for anything you might like to buy across an international …

10 active installs v1.1 PHP + WP 3.0.1+ Updated Mar 1, 2015
affiliateair-ticketsairfaresshoppingtravel
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Online Pre-Travel Shopping Safe to Use in 2026?

Generally Safe

Score 85/100

Online Pre-Travel Shopping has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The 'online-pre-travel-shopping' plugin version 1.1 exhibits a mixed security posture. While the absence of known CVEs and a clean taint analysis are positive indicators, the static analysis reveals significant areas for improvement. The plugin has a small attack surface, but critically, one of its two entry points, an AJAX handler, lacks any authentication or capability checks. This makes it susceptible to unauthorized execution of its functions by unauthenticated users.

Furthermore, a concerning percentage of output is not properly escaped. This could lead to various cross-site scripting (XSS) vulnerabilities if user-supplied data is not neutralized before being displayed in the browser. The lack of nonce checks on the unprotected AJAX handler exacerbates this risk, as an attacker could easily forge requests. The plugin's vulnerability history is clean, which is a strength, but it does not mitigate the immediate risks identified in the current code analysis.

In conclusion, the plugin has potential strengths in its lack of complex vulnerabilities and clean SQL query practices. However, the unprotected AJAX endpoint and insufficient output escaping present immediate and exploitable risks that require attention to harden its security.

Key Concerns

  • Unprotected AJAX handler
  • Insufficient output escaping
  • Missing nonce checks on AJAX
Vulnerabilities
None known

Online Pre-Travel Shopping Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Online Pre-Travel Shopping Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
36
14 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

28% escaped50 total outputs
Attack Surface
1 unprotected

Online Pre-Travel Shopping Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 1

authwp_ajax_theme_update_requestshopnfly-onlinepre-travelshopping.php:105

Shortcodes 1

[sf_travel_shop] controller\cont_admin.php:40
WordPress Hooks 9
actionadmin_menucontroller\cont_admin.php:36
actionadmin_initcontroller\cont_admin.php:38
actionadmin_headcontroller\cont_admin.php:41
filtermce_external_pluginscontroller\cont_admin.php:149
filtermce_buttonscontroller\cont_admin.php:151
actionplugins_loadedshopnfly-onlinepre-travelshopping.php:15
actionwidgets_initshopnfly-onlinepre-travelshopping.php:37
actionadmin_enqueue_scriptsshopnfly-onlinepre-travelshopping.php:59
actionwp_enqueue_scriptsshopnfly-onlinepre-travelshopping.php:72
Maintenance & Trust

Online Pre-Travel Shopping Maintenance & Trust

Maintenance Signals

WordPress version tested4.1.42
Last updatedMar 1, 2015
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Online Pre-Travel Shopping Developer Profile

shopnfly

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Online Pre-Travel Shopping

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/online-pre-travel-shopping/css/farbtastic.css/wp-content/plugins/online-pre-travel-shopping/css/sf_ui.css/wp-content/plugins/online-pre-travel-shopping/css/sf_themes.css/wp-content/plugins/online-pre-travel-shopping/js/sf_admin_jquery.js/wp-content/plugins/online-pre-travel-shopping/js/sf_jquery.js

HTML / DOM Fingerprints

HTML Comments
<!-- widget --><!-- shortcode -->
Data Attributes
sel_themecustom_widthborder_colorbackground_colortext_colorbutton_color+2 more
JS Globals
shortcode_default_rectangleshortcode_default_wideshortcode_default_narrowshortcode_default_dynamic-widthsfts_settings_value
Shortcode Output
[sf_travel_shop]
FAQ

Frequently Asked Questions about Online Pre-Travel Shopping