
OnlineAfspraken Plugin Security & Risk Analysis
wordpress.org/plugins/onlineafspraken-wordpress-pluginMet deze plugin plaatst u de OnlineAfspraken boekingswidget in uw WordPress site.
Is OnlineAfspraken Plugin Safe to Use in 2026?
Generally Safe
Score 85/100OnlineAfspraken Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The onlineafspraken-wordpress-plugin v0.9 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and the absence of any recorded vulnerabilities or CVEs, there are significant areas of concern stemming from the static analysis. The plugin's output is not properly escaped in any of its 45 identified outputs, presenting a high risk of Cross-Site Scripting (XSS) vulnerabilities. Additionally, a flow with an unsanitized path was identified, which could potentially lead to path traversal or other file system vulnerabilities, especially when combined with the presence of the `move_uploaded_file` function, a known sensitive operation.
The lack of nonce checks and capability checks for its single entry point (a shortcode) is a notable weakness. While the static analysis reports only one shortcode and no direct AJAX or REST API endpoints without authentication, the absence of these fundamental security measures on the shortcode leaves it potentially vulnerable to abuse if not handled carefully by the calling context. The vulnerability history being clean is a positive sign, suggesting either responsible development or limited exposure, but it does not negate the risks identified in the current code.
Key Concerns
- 0% properly escaped output
- Flow with unsanitized path
- Dangerous function move_uploaded_file
- No nonce checks
- Insufficient capability checks
OnlineAfspraken Plugin Security Vulnerabilities
OnlineAfspraken Plugin Release Timeline
OnlineAfspraken Plugin Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
OnlineAfspraken Plugin Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
OnlineAfspraken Plugin Maintenance & Trust
Maintenance Signals
Community Trust
OnlineAfspraken Plugin Alternatives
OnlineAfspraken Plugin Developer Profile
1 plugin · 10 total installs
How We Detect OnlineAfspraken Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/onlineafspraken-wordpress-plugin/oa-admin.js/wp-content/plugins/onlineafspraken-wordpress-plugin/oa-admin.css/wp-content/plugins/onlineafspraken-wordpress-plugin/oa-admin.js/wp-content/plugins/onlineafspraken-wordpress-plugin/oa-admin.js?ver=/wp-content/plugins/onlineafspraken-wordpress-plugin/oa-admin.css?ver=HTML / DOM Fingerprints
oa_admin_page_wrapper<!-- Het admin form --><!-- NAAM AANPASSEN (icon url, en bestand)!!! --><!-- zet de plugin menu link --><!-- admin plugin beneer functie -->+3 moredata-apikey-inputdata-oaframewidth-inputdata-oaframeheight-inputdata-select-button-inputdata-align-oa-inputdata-align-oa-button-input+2 moreoa_admin_ajax_object[onlineafspraken]