
Oxtilo Fast Cal Security & Risk Analysis
wordpress.org/plugins/oxtilo-fast-calA secure and flexible booking management system for WordPress with availability handling, ICS sync, and REST API.
Is Oxtilo Fast Cal Safe to Use in 2026?
Generally Safe
Score 100/100Oxtilo Fast Cal has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "oxtilo-fast-cal" plugin version 0.9.8 demonstrates a generally good security posture based on the static analysis. The absence of critical and high-severity taint flows, along with a substantial number of proper SQL prepared statements and a decent percentage of properly escaped outputs, are positive indicators. The plugin also implements a reasonable number of nonce and capability checks, which are essential for securing WordPress functionalities.
However, there are areas that warrant attention. The relatively low percentage of properly escaped outputs (54%) suggests a potential risk of Cross-Site Scripting (XSS) vulnerabilities if certain output functionalities are not handled with sufficient sanitization. While no specific XSS vulnerabilities were flagged in the taint analysis, this percentage indicates a weakness that could be exploited. The single file operation and external HTTP request, while not inherently dangerous, are always potential entry points for vulnerabilities if not secured correctly.
Given that there are no recorded CVEs for this plugin, its vulnerability history is a strength, indicating a track record of security. The lack of past vulnerabilities could suggest either a well-maintained codebase or simply a lack of discovered issues. Overall, the plugin has a solid foundation, but the unescaped output is the most significant concern, requiring careful review and remediation.
Key Concerns
- Low percentage of properly escaped outputs
Oxtilo Fast Cal Security Vulnerabilities
Oxtilo Fast Cal Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Oxtilo Fast Cal Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 24
Scheduled Events 1
Maintenance & Trust
Oxtilo Fast Cal Maintenance & Trust
Maintenance Signals
Community Trust
Oxtilo Fast Cal Alternatives
MotoPress Appointment Booking
motopress-appointment-lite
MotoPress Appointment Booking makes it easy for time and service-based businesses to accept bookings and appointments online.
SimplyBook.me – Booking and reservations calendar
simplybook
Simply add a booking calendar to your site to schedule bookings, reservations, appointments and to collect payments.
Appointment Hour Booking – Booking Calendar
appointment-hour-booking
Appointment Hour Booking is a plugin for creating booking forms for appointments with a start time and a defined duration within a schedule.
Booking Package
booking-package
Booking Package is the simplest solution for integrating an online appointment booking calendar system and event calendar into your WordPress website.
Easy Appointments
easy-appointments
Add Booking system to your WordPress site and manage Appointments with ease. Extremely flexible time management and custom email notifications.
Oxtilo Fast Cal Developer Profile
1 plugin · 0 total installs
How We Detect Oxtilo Fast Cal
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/oxtilo-fast-cal/assets/oxtilofastcal-admin.css/wp-content/plugins/oxtilo-fast-cal/assets/oxtilofastcal-admin.js/wp-content/plugins/oxtilo-fast-cal/assets/oxtilofastcal-admin.jsoxtilo-fast-cal/assets/oxtilofastcal-admin.css?ver=oxtilo-fast-cal/assets/oxtilofastcal-admin.js?ver=HTML / DOM Fingerprints
oxtilofastcal-admin-wrapdata-nonce="wp_create_nonce( 'oxtilofastcal_generate_calendar_token' )"data-nonce="wp_create_nonce( 'oxtilofastcal_test_ics_feed' )"data-nonce="wp_create_nonce( 'oxtilofastcal_diagnostics' )"oxtilofastcalAdmin/wp-json/oxtilofastcal/v1/booking/wp-json/oxtilofastcal/v1/booking/(?P<id>\d+)/wp-json/oxtilofastcal/v1/availability/wp-json/oxtilofastcal/v1/availability/(?P<id>\d+)/wp-json/oxtilofastcal/v1/booking-meta/wp-json/oxtilofastcal/v1/settings/wp-json/oxtilofastcal/v1/templates/wp-json/oxtilofastcal/v1/template/(?P<id>\d+)/wp-json/oxtilofastcal/v1/diagnostics/wp-json/oxtilofastcal/v1/feed[oxtilo_fast_cal][oxtilo_fast_cal_booking]