OzonTravel: Flights,Hotels,Railways,Insurance Security & Risk Analysis

wordpress.org/plugins/ozontravelwidget

Travel tools to find flights, hotels, railways and insurance.

10 active installs v0.1a PHP + WP + Updated Aug 16, 2016
aviaflightshotelsozonozontravel
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is OzonTravel: Flights,Hotels,Railways,Insurance Safe to Use in 2026?

Generally Safe

Score 85/100

OzonTravel: Flights,Hotels,Railways,Insurance has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The ozontravelwidget plugin v0.1a presents a mixed security posture. While the static analysis reveals no direct vulnerabilities such as dangerous functions, raw SQL queries, or obvious taint flows, there are significant areas of concern stemming from a lack of protective measures. The absence of any identified attack surface points (AJAX handlers, REST API routes, shortcodes, cron events) is unusual for a plugin and could indicate a very limited functionality or a misinterpretation of the analysis. More critically, the plugin exhibits a concerning lack of capability and nonce checks, meaning any functionality it does expose might be accessible without proper authentication or authorization. The low percentage of properly escaped output (36%) is a substantial risk, potentially leading to Cross-Site Scripting (XSS) vulnerabilities if any user-supplied data is rendered without sanitization.

The vulnerability history is clean, with no recorded CVEs. This, combined with the limited code signals of concern (beyond output escaping), could suggest a well-developed plugin or, conversely, that the plugin's limited functionality has not yet attracted security scrutiny or that the analysis might not be fully comprehensive. The strengths lie in the absence of known vulnerabilities and the use of prepared statements for any SQL queries (though none were found in this analysis). However, the weaknesses are significant, primarily the poor output escaping and the lack of robust security checks for potential entry points. The current version should be used with extreme caution due to the high risk of XSS.

Key Concerns

  • Poor output escaping (36% proper)
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

OzonTravel: Flights,Hotels,Railways,Insurance Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

OzonTravel: Flights,Hotels,Railways,Insurance Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
16
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

36% escaped25 total outputs
Attack Surface

OzonTravel: Flights,Hotels,Railways,Insurance Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initOzonTravelWidget.php:77
Maintenance & Trust

OzonTravel: Flights,Hotels,Railways,Insurance Maintenance & Trust

Maintenance Signals

WordPress version tested
Last updatedAug 16, 2016
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

OzonTravel: Flights,Hotels,Railways,Insurance Developer Profile

ozontravel

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect OzonTravel: Flights,Hotels,Railways,Insurance

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<iframe src="//partners.ozon.travel/searchform_v2_0/?forpartner=&formOrientation=vertical&" height="500px" width="200px"scrolling="no" frameborder="0"></iframe>
FAQ

Frequently Asked Questions about OzonTravel: Flights,Hotels,Railways,Insurance