Planaday Connector Security & Risk Analysis

wordpress.org/plugins/planaday-connector

Toon het cursusaanbod vanuit Planaday op jouw website met de verschillende shortcodes die deze WordPress plugin beschikbaar stelt.

10 active installs v1.2.0 PHP 8.1+ WP 5.9+ Updated Mar 12, 2026
administratieboekingconnectorcursusplanning
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Planaday Connector Safe to Use in 2026?

Generally Safe

Score 100/100

Planaday Connector has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 28d ago
Risk Assessment

The 'planaday-connector' plugin version 1.2.0 exhibits a mixed security posture. On the positive side, the static analysis shows a complete absence of known CVEs and a lack of critical or high-severity findings in taint analysis, suggesting a generally clean codebase regarding historical and deep code vulnerabilities. The plugin also uses prepared statements for all its SQL queries, which is a strong defense against SQL injection. Furthermore, it demonstrates some use of nonce and capability checks, indicating an awareness of WordPress security best practices.

However, there are notable areas for improvement. The most significant concern is the extremely low percentage of properly escaped output (only 6%). This suggests a high risk of Cross-Site Scripting (XSS) vulnerabilities. While the taint analysis did not reveal any unsanitized paths, the low output escaping rate means that any data processed and outputted without explicit sanitization could be exploited. Additionally, the presence of file operations and external HTTP requests without clear indications of sanitization or validation is a potential concern, although the attack surface from direct entry points like AJAX, REST API, and shortcodes appears to be well-protected.

Overall, while the plugin has a clean vulnerability history and avoids common pitfalls like raw SQL queries and exploitable entry points, the pervasive issue with output escaping significantly lowers its security score. The plugin appears to have a solid foundation in preventing direct attacks through its limited attack surface, but the lack of robust output sanitization leaves it vulnerable to XSS attacks, which can have severe consequences. Addressing the output escaping is paramount to improving its security.

Key Concerns

  • Low output escaping rate (6%)
Vulnerabilities
None known

Planaday Connector Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Planaday Connector Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Planaday Connector Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
35 prepared
Unescaped Output
30
2 escaped
Nonce Checks
2
Capability Checks
2
File Operations
18
External Requests
2
Bundled Libraries
1

Bundled Libraries

TinyMCE

SQL Query Safety

100% prepared35 total queries

Output Escaping

6% escaped32 total outputs
Attack Surface

Planaday Connector Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 21
actionrest_api_initsrc\Planaday\Payment\Mollie\Mollie.php:36
filterblock_categories_allsrc\Planaday\Platform\WordpressConfig\Blocks\BlockHandler.php:32
actionrest_api_initsrc\Planaday\Platform\WordpressConfig\Blocks\BlockHandler.php:82
actioninitsrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:70
actioninitsrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:71
actioninitsrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:72
actioninitsrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:73
actioninitsrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:74
actionwidgets_initsrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:75
actionrest_api_initsrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:76
actionwp_footersrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:77
actionin_admin_footersrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:78
actionelementor/editor/before_enqueue_scriptssrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:80
actionelementor/editor/before_enqueue_scriptssrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:81
actionadmin_enqueue_scriptssrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:85
actionadmin_menusrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:86
actionadmin_noticessrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:87
filterquery_varssrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:92
filterrewrite_rules_arraysrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:93
actionwp_footersrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:322
actionin_admin_footersrc\Planaday\Platform\WordpressConfig\WPPlatformService.php:323
Maintenance & Trust

Planaday Connector Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 12, 2026
PHP min version8.1
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Planaday Connector Developer Profile

Planaday Developers

2 plugins · 30 total installs

100
trust score
Avg Security Score
100/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Planaday Connector

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/planaday-connector/src/Planaday/Platform/WordpressConfig/Blocks/Blocks.js/wp-content/plugins/planaday-connector/src/Planaday/Platform/WordpressConfig/AdminGUI/AdminGUI.js/wp-content/plugins/planaday-connector/src/Planaday/Platform/WordpressConfig/Assets/js/functions.js
Script Paths
/wp-content/plugins/planaday-connector/src/Planaday/Platform/WordpressConfig/Blocks/Blocks.js/wp-content/plugins/planaday-connector/src/Planaday/Platform/WordpressConfig/AdminGUI/AdminGUI.js/wp-content/plugins/planaday-connector/src/Planaday/Platform/WordpressConfig/Assets/js/functions.js
Version Parameters
planaday-connector/src/Planaday/Platform/WordpressConfig/Assets/js/functions.js?ver=planaday-connector/src/Planaday/Platform/WordpressConfig/Blocks/Blocks.js?ver=planaday-connector/src/Planaday/Platform/WordpressConfig/AdminGUI/AdminGUI.js?ver=

HTML / DOM Fingerprints

CSS Classes
planaday-connector
HTML Comments
Plugin Name: Planaday ConnectorPlugin URI: https://planaday.freshdesk.com/support/solutions/articles/11000058859-wordpress-in-website-met-publieke-apiDescription: Toon het cursusaanbod vanuit Planaday op jouw website met de verschillende shortcodes die deze WordPress plugin beschikbaar steltVersion: 1.2.0+7 more
Data Attributes
data-planaday-connector-id
JS Globals
window.planaday_connector_admin_paramswindow.planaday_connector_functionswindow.PlanadayConnectorwindow.PlanadayBlocks
REST Endpoints
/wp-json/planaday-connector/
Shortcode Output
[planaday_course_calendar][planaday_course_list][planaday_course_detail][planaday_testing_shortcode]
FAQ

Frequently Asked Questions about Planaday Connector