Oryx Bookings: WooCommerce Appointments & Scheduling (100% Free) Security & Risk Analysis

wordpress.org/plugins/oryx-bookings

The only 100% FREE Booking Plugin with WooCommerce Payments, Unlimited Staff, and 6 Premium Templates. No hidden costs.

90 active installs v1.1.3 PHP 7.4+ WP 6.0+ Updated Feb 9, 2026
appointmentbookingcalendarschedulingwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Oryx Bookings: WooCommerce Appointments & Scheduling (100% Free) Safe to Use in 2026?

Generally Safe

Score 100/100

Oryx Bookings: WooCommerce Appointments & Scheduling (100% Free) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6mo ago
Risk Assessment

The Oryx Bookings plugin version 1.1.3 exhibits a generally strong security posture, with a significant emphasis on secure coding practices. The static analysis reveals a robust implementation of prepared statements for SQL queries (84%) and excellent output escaping (99%), significantly reducing the risk of common web vulnerabilities like SQL injection and cross-site scripting. The plugin also demonstrates a healthy use of nonce and capability checks, further hardening its entry points, which are all protected by authentication mechanisms.

However, the taint analysis flags a concerning pattern. While no critical or high severity taint flows were identified, there are 17 high severity flows with unsanitized paths. This indicates a substantial number of instances where user-supplied data might be processed in a way that could lead to unexpected or insecure behavior, even if not immediately exploitable as a critical vulnerability. The absence of any known CVEs is a positive sign, suggesting a history of responsible development. Nonetheless, the high number of unsanitized paths in the taint analysis warrants careful investigation to ensure these flows do not represent potential security weaknesses.

In conclusion, Oryx Bookings version 1.1.3 has a commendable foundation in security. The developers have prioritized fundamental security controls like prepared statements and output escaping. The main area for improvement lies in thoroughly auditing and sanitizing the identified 17 high-severity taint flows. Addressing these could further solidify the plugin's security and prevent potential future vulnerabilities.

Key Concerns

  • High severity taint flows with unsanitized paths
Vulnerabilities
None known

Oryx Bookings: WooCommerce Appointments & Scheduling (100% Free) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Oryx Bookings: WooCommerce Appointments & Scheduling (100% Free) Release Timeline

v1.1.3Current
v1.1.2
v1.1.1
v1.1.0
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Oryx Bookings: WooCommerce Appointments & Scheduling (100% Free) Code Analysis

Dangerous Functions
0
Raw SQL Queries
19
101 prepared
Unescaped Output
7
1067 escaped
Nonce Checks
28
Capability Checks
17
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

84% prepared120 total queries

Output Escaping

99% escaped1074 total outputs
Data Flows · Security
22 unsanitized

Data Flow Analysis

25 flows22 with unsanitized paths
render_list (src\Admin\CategoriesController.php:152)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Oryx Bookings: WooCommerce Appointments & Scheduling (100% Free) Attack Surface

Entry Points12
Unprotected0

AJAX Handlers 10

authwp_ajax_oryx_calendar_get_eventssrc\Admin\CalendarController.php:35
authwp_ajax_oryx_calendar_update_bookingsrc\Admin\CalendarController.php:36
authwp_ajax_oryx_calendar_delete_bookingsrc\Admin\CalendarController.php:37
authwp_ajax_oryx_calendar_create_bookingsrc\Admin\CalendarController.php:38
authwp_ajax_oryx_bookings_get_slotssrc\Presentation\Frontend\Shortcodes.php:47
noprivwp_ajax_oryx_bookings_get_slotssrc\Presentation\Frontend\Shortcodes.php:48
authwp_ajax_oryx_bookings_create_bookingsrc\Presentation\Frontend\Shortcodes.php:49
noprivwp_ajax_oryx_bookings_create_bookingsrc\Presentation\Frontend\Shortcodes.php:50
authwp_ajax_oryx_bookings_get_available_datessrc\Presentation\Frontend\Shortcodes.php:51
noprivwp_ajax_oryx_bookings_get_available_datessrc\Presentation\Frontend\Shortcodes.php:52

Shortcodes 2

[oryx_bookings] src\Presentation\Frontend\Shortcodes.php:43
[oryx_bookings_my_bookings] src\Presentation\Frontend\Shortcodes.php:44
WordPress Hooks 33
actionadmin_enqueue_scriptssrc\Admin\CalendarController.php:39
actionadmin_initsrc\Admin\CategoriesController.php:25
actionadmin_menusrc\Admin\MenuManager.php:45
actionadmin_initsrc\Admin\MenuManager.php:46
actionadmin_enqueue_scriptssrc\Admin\MenuManager.php:47
actionadmin_initsrc\Admin\ServicesController.php:41
actionadmin_enqueue_scriptssrc\Admin\ServicesController.php:42
actionadmin_initsrc\Admin\SettingsController.php:17
actionadmin_initsrc\Admin\StaffController.php:38
actionadmin_enqueue_scriptssrc\Admin\StaffController.php:39
actionwp_enqueue_scriptssrc\Elementor\AssetsLoader.php:32
actionelementor/frontend/after_enqueue_scriptssrc\Elementor\AssetsLoader.php:33
actionplugins_loadedsrc\Elementor\ElementorLoader.php:43
actionadmin_noticessrc\Elementor\ElementorLoader.php:58
actionelementor/widgets/registersrc\Elementor\ElementorLoader.php:66
actionelementor/elements/categories_registeredsrc\Elementor\ElementorLoader.php:69
actionelementor/editor/before_enqueue_scriptssrc\Elementor\ElementorLoader.php:72
actionelementor/preview/enqueue_stylessrc\Elementor\ElementorLoader.php:75
filterblock_categories_allsrc\Gutenberg\GutenbergLoader.php:36
actioninitsrc\Gutenberg\GutenbergLoader.php:37
actionenqueue_block_editor_assetssrc\Gutenberg\GutenbergLoader.php:38
actionwoocommerce_order_status_processingsrc\Integrations\WooCommerceIntegration.php:24
actionwoocommerce_order_status_completedsrc\Integrations\WooCommerceIntegration.php:25
actionwoocommerce_order_status_cancelledsrc\Integrations\WooCommerceIntegration.php:26
actionwoocommerce_order_status_refundedsrc\Integrations\WooCommerceIntegration.php:27
actionwoocommerce_order_status_failedsrc\Integrations\WooCommerceIntegration.php:28
actionwoocommerce_product_querysrc\Integrations\WooCommerceIntegration.php:31
filterwoocommerce_order_item_namesrc\Integrations\WooCommerceIntegration.php:32
actionplugins_loadedsrc\Plugin.php:26
actionplugins_loadedsrc\Plugin.php:29
actionwp_enqueue_scriptssrc\Presentation\Frontend\Shortcodes.php:55
filterwp_privacy_personal_data_exporterssrc\Privacy\PersonalDataHandler.php:17
filterwp_privacy_personal_data_eraserssrc\Privacy\PersonalDataHandler.php:18
Maintenance & Trust

Oryx Bookings: WooCommerce Appointments & Scheduling (100% Free) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedFeb 9, 2026
PHP min version7.4
Downloads870

Community Trust

Rating0/100
Number of ratings0
Active installs90
Developer Profile

Oryx Bookings: WooCommerce Appointments & Scheduling (100% Free) Developer Profile

Rabie Eltegani

1 plugin · 90 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Oryx Bookings: WooCommerce Appointments & Scheduling (100% Free)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/oryx-bookings/src/Presentation/Admin/assets/css/calendar.css/wp-content/plugins/oryx-bookings/src/Presentation/Admin/assets/js/calendar.js
Script Paths
/wp-content/plugins/oryx-bookings/node_modules/@fullcalendar/core/index.global.min.js/wp-content/plugins/oryx-bookings/node_modules/@fullcalendar/daygrid/index.global.min.js/wp-content/plugins/oryx-bookings/node_modules/@fullcalendar/timegrid/index.global.min.js/wp-content/plugins/oryx-bookings/node_modules/@fullcalendar/list/index.global.min.js/wp-content/plugins/oryx-bookings/node_modules/@fullcalendar/interaction/index.global.min.js/wp-content/plugins/oryx-bookings/src/Presentation/Admin/assets/js/calendar.js
Version Parameters
oryx-bookings/src/Presentation/Admin/assets/css/calendar.css?ver=oryx-bookings/src/Presentation/Admin/assets/js/calendar.js?ver=

HTML / DOM Fingerprints

CSS Classes
oryx-calendar-css
Data Attributes
data-ajaxurldata-noncedata-staffdata-servicesdata-companydaysoffdata-closedweekdays+21 more
JS Globals
oryxCalendar
REST Endpoints
/wp-json/oryx-bookings/v1/bookings/wp-json/oryx-bookings/v1/staff/wp-json/oryx-bookings/v1/services/wp-json/oryx-bookings/v1/availability/wp-json/oryx-bookings/v1/company-days-off/wp-json/oryx-bookings/v1/company-working-hours
FAQ

Frequently Asked Questions about Oryx Bookings: WooCommerce Appointments & Scheduling (100% Free)