
Redforts Hotel Booking Engine Security & Risk Analysis
wordpress.org/plugins/oscar-hotel-booking-engineThis plugin integrates with Redforts Hotel Software, the all-in-one solution for hotels, hostels, apartments, villas, campings, and more.
Is Redforts Hotel Booking Engine Safe to Use in 2026?
Generally Safe
Score 100/100Redforts Hotel Booking Engine has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "oscar-hotel-booking-engine" plugin v4.10 presents a mixed security posture. On the positive side, the plugin has no recorded CVEs, a clean vulnerability history, and a very limited attack surface with no identified unprotected entry points. The static analysis also indicates a reasonable number of capability checks and a nonce check present, suggesting some attention to security fundamentals. However, several areas raise concerns. The plugin utilizes raw SQL queries without prepared statements, which is a significant risk for SQL injection vulnerabilities, especially if any part of the query is derived from user input, even if not immediately obvious from the provided data. Furthermore, only 20% of output escaping is properly handled, leaving a substantial portion vulnerable to Cross-Site Scripting (XSS) attacks.
While the taint analysis shows no detected flows, this might be due to the limitations of the analysis itself or the specific code paths examined. The presence of raw SQL and poor output escaping are critical vulnerabilities that could be exploited even without complex taint flows. The file operations and external HTTP requests, while not flagged as immediately dangerous, warrant careful review in conjunction with the other identified weaknesses. The absence of known vulnerabilities is a positive sign, but it does not negate the inherent risks identified in the code. The plugin's overall security is hampered by the critical risk of SQL injection and XSS due to insufficient sanitization and escaping practices, despite a seemingly low attack surface and clean history.
Key Concerns
- Raw SQL queries without prepared statements
- Low percentage of properly escaped output
Redforts Hotel Booking Engine Security Vulnerabilities
Redforts Hotel Booking Engine Code Analysis
SQL Query Safety
Output Escaping
Redforts Hotel Booking Engine Attack Surface
Shortcodes 2
WordPress Hooks 20
Maintenance & Trust
Redforts Hotel Booking Engine Maintenance & Trust
Maintenance Signals
Community Trust
Redforts Hotel Booking Engine Alternatives
IdoBooking
booking-calendar-with-availability-management
Add a calendar to a reservation of: a room, suite, night or an attraction. The system sends emails, calculates payments and updates availability.
VikBooking Hotel Booking Engine & PMS
vikbooking
Famous Booking Engine, PMS and Hotel Reservations plugin for property managers. The best solution for accommodations to drive more direct bookings.
Jomres Hotel Booking Engine for WordPress
jomres
Build your own Online Travel Agency like Booking.com or AirBNB
1Day Booking Engine
1day-io
Simple, modern and flexible booking engine for your hotel. Let customers book rooms easily without being redirected away from your website.
Rise Hotel Booking
rise-hotel-booking
Rise Hotel Booking is an easy to use reservation system for hotels and apartment rentals. Get your bookings directly on your site!
Redforts Hotel Booking Engine Developer Profile
1 plugin · 300 total installs
How We Detect Redforts Hotel Booking Engine
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oscar-hotel-booking-engine/assets/css/datepicker.css/wp-content/plugins/oscar-hotel-booking-engine/assets/css/ohbe-style.css/wp-content/plugins/oscar-hotel-booking-engine/assets/js/countdown.js/wp-content/plugins/oscar-hotel-booking-engine/assets/js/custom.js/wp-content/plugins/oscar-hotel-booking-engine/assets/js/datepicker.js/wp-content/plugins/oscar-hotel-booking-engine/assets/js/moment.min.js/wp-content/plugins/oscar-hotel-booking-engine/assets/js/owl.carousel.min.js/wp-content/plugins/oscar-hotel-booking-engine/assets/js/countdown.js/wp-content/plugins/oscar-hotel-booking-engine/assets/js/custom.js/wp-content/plugins/oscar-hotel-booking-engine/assets/js/datepicker.js/wp-content/plugins/oscar-hotel-booking-engine/assets/js/moment.min.js/wp-content/plugins/oscar-hotel-booking-engine/assets/js/owl.carousel.min.jsoscar-hotel-booking-engine/assets/css/datepicker.css?ver=oscar-hotel-booking-engine/assets/css/ohbe-style.css?ver=oscar-hotel-booking-engine/assets/js/countdown.js?ver=oscar-hotel-booking-engine/assets/js/custom.js?ver=oscar-hotel-booking-engine/assets/js/datepicker.js?ver=oscar-hotel-booking-engine/assets/js/moment.min.js?ver=oscar-hotel-booking-engine/assets/js/owl.carousel.min.js?ver=HTML / DOM Fingerprints
ohbe-booking-engineohbe-booking-formohbe-room-availabilityohbe-booking-confirmationohbe-booking-calendarohbe-datepicker<!-- Show more options --><!-- Load the full calendar and its dependencies --><!-- Set the default view --><!-- Render the calendar -->+2 moredata-plugin-pathdata-current-pagedata-ajax-urldata-localedata-date-formatOHBE_BookingOHBE_AvailabilityOHBE_ConfirmationOHBE_Config/wp-json/ohbe/v1/availability/wp-json/ohbe/v1/booking/wp-json/ohbe/v1/hotels[oscar_hotel_booking][oscar_hotel_availability][oscar_hotel_confirmation][oscar_hotel_search]