
OwnerRez Security & Risk Analysis
wordpress.org/plugins/ownerrezThe official WordPress plugin for the OwnerRez API.
Is OwnerRez Safe to Use in 2026?
Generally Safe
Score 98/100OwnerRez has a strong security track record. Known vulnerabilities have been patched promptly.
The ownerrez plugin v1.2.6 exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and includes nonce and capability checks for its entry points, significant concerns remain. The presence of two AJAX handlers without authentication checks represents a substantial attack surface, making it vulnerable to unauthorized actions if these endpoints can be triggered externally. Furthermore, the taint analysis revealing two flows with unsanitized paths, though not classified as critical or high severity, suggests potential for subtle vulnerabilities in how input is processed. The plugin's vulnerability history, with two past medium-severity CVEs for Cross-site Scripting and Cross-Site Request Forgery, indicates a pattern of past security weaknesses, even though there are no currently unpatched vulnerabilities. This history, coupled with the identified unprotected AJAX handlers, suggests a need for continued vigilance and thorough code review.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Past medium severity CVEs
OwnerRez Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
OwnerRez <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
OwnerRez <= 1.2.0 - Cross-Site Request Forgery
OwnerRez Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
OwnerRez Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
OwnerRez Maintenance & Trust
Maintenance Signals
Community Trust
OwnerRez Alternatives
Booking Engine by Lodgify
lodgify-booking-engine
Easy to use booking engine for your vacation rental website. List your rentals on your site and save on commissions (from big OTA's).
Domilocus
domilocus
Complete booking and property management solution for vacation rentals, apartments, and accommodations with backend administration.
Simple rental system
single-page-booking-system
This WordPress plugin integrates the simple rental booking system from i-rent.net into a selected page on the user’s website.
WP Airbnb Review Slider
wp-airbnb-review-slider
Download and display your Airbnb business reviews in your Posts, Pages, and Widget areas with a review slider!
iGMS Direct Booking
igms-direct-booking
iGMS is introducing the Direct Booking Widget. It allows your guests to select and book dates with you right via your website.
OwnerRez Developer Profile
1 plugin · 700 total installs
How We Detect OwnerRez
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ownerrez/admin/css/ownerrez-admin.css/wp-content/plugins/ownerrez/admin/js/ownerrez-admin.jsownerrez/admin/css/ownerrez-admin.css?ver=ownerrez/admin/js/ownerrez-admin.js?ver=HTML / DOM Fingerprints
ownerrez-settings<!-- OwnerRez Settings --><!-- This is the main section for ownerrez settings -->data-ownerrez-api-rootdata-ownerrez-usernamedata-ownerrez-tokenownerrezApiRootownerrezUsernameownerrezToken/wp-json/ownerrez/v1/settings[ownerrez_booking_widget]