Orufy Bookings Security & Risk Analysis

wordpress.org/plugins/orufy-bookings

Seamlessly integrate Orufy booking widgets into your WordPress site. Manage API credentials, select events, and embed booking widgets or popups using …

0 active installs v1.0.0 PHP + WP 1.0+ Updated Aug 19, 2025
bookingcalendarevent-bookingorufywidget-shortcode
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Orufy Bookings Safe to Use in 2026?

Generally Safe

Score 100/100

Orufy Bookings has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9mo ago
Risk Assessment

The "orufy-bookings" v1.0.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, the consistent use of prepared statements for all SQL queries, and the proper escaping of all output indicate good development practices. Furthermore, the plugin demonstrates a commendable approach to security by implementing nonce and capability checks on its entry points, and it has no recorded history of vulnerabilities, which suggests a commitment to maintaining a secure codebase. The lack of known CVEs and the clean taint analysis further reinforce this positive assessment.

However, there are minor areas for attention. The presence of external HTTP requests introduces a potential vector for supply chain attacks or issues if the external service becomes compromised or unavailable. While the number of entry points (shortcodes) is small and appears protected, a larger attack surface could present challenges in maintaining security. The plugin's current version, 1.0.0, also means it's relatively new, and as it matures, further vigilance will be required to prevent the introduction of vulnerabilities.

In conclusion, "orufy-bookings" v1.0.0 is a well-developed plugin with robust security fundamentals. The identified strengths significantly outweigh the minor concerns. The absence of critical vulnerabilities in its history and analysis is a strong positive indicator. The key for continued security will be ongoing diligent development practices, especially as new features are added or the plugin is updated.

Key Concerns

  • External HTTP requests detected
  • Plugin version 1.0.0 is recent
Vulnerabilities
None known

Orufy Bookings Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Orufy Bookings Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

Orufy Bookings Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
42 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

100% escaped42 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

2 flows
orufy_booking_save_settings (admin/bookings/rest/settings-handler.php:7)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Orufy Bookings Attack Surface

Entry Points3
Unprotected0

Shortcodes 3

[orufy-booking-inline] website/bookings/booking-shortcodes.php:62
[orufy-booking-popup-widget] website/bookings/booking-shortcodes.php:81
[orufy-booking-popup-text] website/bookings/booking-shortcodes.php:105
WordPress Hooks 8
actionadmin_menuadmin/bookings/index.php:9
actionadmin_enqueue_scriptsadmin/bookings/index.php:10
actionadmin_post_orufy_booking_save_settingsadmin/bookings/rest/settings-handler.php:56
actionadmin_post_orufy_booking_select_eventadmin/bookings/rest/settings-handler.php:59
actionadmin_enqueue_scriptsadmin/index.php:15
actionwp_enqueue_scriptswebsite/bookings/booking-shortcodes.php:5
actionthe_postswebsite/bookings/booking-shortcodes.php:25
actionwp_enqueue_scriptswebsite/bookings/booking-shortcodes.php:37
Maintenance & Trust

Orufy Bookings Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 19, 2025
PHP min version
Downloads245

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Orufy Bookings Developer Profile

Orufy

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Orufy Bookings

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/orufy-bookings/admin/bookings/assets/css/admin.css/wp-content/plugins/orufy-bookings/admin/bookings/assets/css/admin.csshttps://orufybookings.com/external/widget.csshttps://orufybookings.com/external/widget.js
Script Paths
https://orufybookings.com/external/widget.js
Version Parameters
orufy-bookings/admin/bookings/assets/css/admin.css?ver=1.0.0

HTML / DOM Fingerprints

CSS Classes
orufy-booking-adminorufy-bookings-inline-widget
Data Attributes
data-access-link
JS Globals
orufyBookings
Shortcode Output
<div style="height:100dvh" class="orufy-bookings-inline-widget"<a href="#" onclick="if(typeof orufyBookings !== 'undefined'){orufyBookings.PopUpLink({ AccessLink: 'return false;">Book an event
FAQ

Frequently Asked Questions about Orufy Bookings