
OpenCabs – Taxi and private hire bookings Security & Risk Analysis
wordpress.org/plugins/opencabs-taxi-and-private-hire-bookingsOpenCabs taxi bookings snippet creator.
Is OpenCabs – Taxi and private hire bookings Safe to Use in 2026?
Generally Safe
Score 85/100OpenCabs – Taxi and private hire bookings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "opencabs-taxi-and-private-hire-bookings" v1.2 plugin exhibits a generally good security posture based on the provided static analysis. The absence of detected AJAX handlers, REST API routes, and cron events without authentication, along with no critical or high severity taint flows, is commendable. The plugin also demonstrates good practices by exclusively using prepared statements for SQL queries. However, a significant concern lies in the output escaping, where 52% of outputs are not properly escaped, potentially exposing the application to Cross-Site Scripting (XSS) vulnerabilities. While the vulnerability history is clean, indicating a lack of publicly known exploits, this should not be a sole reason for complacency, especially given the output escaping issues.
The limited attack surface is a strength, with only one shortcode identified as an entry point, and it appears to have an implicit or explicit protection mechanism. The presence of nonce checks and capability checks, though limited in number, suggests an awareness of security best practices. The four external HTTP requests are noted, but without further context, their security implications are unknown. The lack of dangerous functions and file operations is a positive indicator. Overall, the plugin is relatively secure, but the significant percentage of unescaped output represents a notable risk that requires immediate attention and remediation.
Key Concerns
- Significant percentage of unescaped output
OpenCabs – Taxi and private hire bookings Security Vulnerabilities
OpenCabs – Taxi and private hire bookings Code Analysis
Output Escaping
Data Flow Analysis
OpenCabs – Taxi and private hire bookings Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
OpenCabs – Taxi and private hire bookings Maintenance & Trust
Maintenance Signals
Community Trust
OpenCabs – Taxi and private hire bookings Alternatives
E-cab Taxi Booking Manager for Woocommerce
ecab-taxi-booking-manager
Taxi Booking & Cab Booking for WooCommerce. Chauffeur service with fare calculator, distance pricing, and OpenStreetMap.
Cab fare calculator
cab-fare-calculator
This plugin will add an online taxi booking form on your WordPress website. You will be able to manage your vehicles and orders through the back end.
Transporters.io
transportersio
Easily add Transporters.io quote forms to your site. Ideal for minibus, coach and bus hire / charter - specifically prebooked private hire.
Cab Grid
cab-grid
Easily add a taxi fare price calculator to your website via shortcode [cabGrid] or widget. Simply enter journey prices in a table.
Chauffeur Booking
chauffeur-booking
A vehicle booking system with Google Maps integration, flexible pricing, and complete booking management.
OpenCabs – Taxi and private hire bookings Developer Profile
1 plugin · 10 total installs
How We Detect OpenCabs – Taxi and private hire bookings
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/opencabs-taxi-and-private-hire-bookings/css/bootstrap.min.css/wp-content/plugins/opencabs-taxi-and-private-hire-bookings/css/bootstrap-theme.min.css/wp-content/plugins/opencabs-taxi-and-private-hire-bookings/css/ubicabs.css/wp-content/plugins/opencabs-taxi-and-private-hire-bookings/js/bootstrap.min.js/wp-content/plugins/opencabs-taxi-and-private-hire-bookings/js/bootstrap.min.jsHTML / DOM Fingerprints
hiddenid="opencabs_field_nodeId"id="opencabs_field_publisherId"id="opencabs_field_publisher_name"id="opencabs_field_token"id="opencabs_field_username"id="opencabs_field_password"