Planyo online reservation system Security & Risk Analysis

wordpress.org/plugins/planyo-online-reservation-system

This plugin embeds the Planyo online reservation system.

400 active installs v3.1 PHP + WP 2.5+ Updated Mar 23, 2026
bookbookingreservationreservesystem
73
B · Generally Safe
CVEs total2
Unpatched1
Last CVEJul 10, 2026
Safety Verdict

Is Planyo online reservation system Safe to Use in 2026?

Mostly Safe

Score 73/100

Planyo online reservation system is generally safe to use. 2 past CVEs were resolved.

2 known CVEs 1 unpatched Last CVE: Jul 10, 2026Updated 3mo ago
Risk Assessment

The 'planyo-online-reservation-system' plugin v3.0 exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and has no identified critical or high severity vulnerabilities in its static analysis, several significant concerns remain. The complete lack of proper output escaping across all identified output points is a major red flag, leaving the plugin highly susceptible to Cross-Site Scripting (XSS) attacks. Furthermore, the absence of nonce checks and capability checks on its entry points (even though the attack surface is currently small) means that any future introduction of new handlers or features could introduce vulnerabilities if not carefully secured. The plugin also has a history of a medium severity Cross-Site Scripting vulnerability, with one currently unpatched. This pattern, coupled with the current lack of output escaping, suggests a potential ongoing weakness in how user-provided data is handled, which could be exploited if an attacker finds a way to inject malicious scripts.

Key Concerns

  • Unpatched medium CVE
  • Output escaping 0%
  • No nonce checks
  • No capability checks
  • Flows with unsanitized paths
Vulnerabilities
2 published

Planyo online reservation system Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2026-3576high · 7.2Improper Input Validation

Planyo online reservation system <= 3.0 - Unauthenticated Server-Side Request Forgery via 'ulap_url' Parameter

Jul 10, 2026 Patched in 3.1 (1d)
CVE-2025-31811medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Planyo online reservation system <= 3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 1, 2025Unpatched
Version History

Planyo online reservation system Release Timeline

Code Analysis
Analyzed Mar 16, 2026

Planyo online reservation system Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

0% escaped22 total outputs
Data Flows · Security
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
planyo_output_resource_details (planyo-plugin-impl.php:149)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Planyo online reservation system Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[planyo] planyo.php:277
WordPress Hooks 3
actionadmin_initplanyo.php:31
actionadmin_menuplanyo.php:203
actioninitplanyo.php:206
Maintenance & Trust

Planyo online reservation system Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 23, 2026
PHP min version
Downloads18K

Community Trust

Rating0/100
Number of ratings0
Active installs400
Developer Profile

Planyo online reservation system Developer Profile

xtreeme

1 plugin · 400 total installs

81
trust score
Avg Security Score
73/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Planyo online reservation system

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/planyo-online-reservation-system/planyo.css/wp-content/plugins/planyo-online-reservation-system/planyo_admin.css/wp-content/plugins/planyo-online-reservation-system/planyo.js/wp-content/plugins/planyo-online-reservation-system/planyo_admin.js
Version Parameters
planyo-online-reservation-system/planyo.css?ver=planyo-online-reservation-system/planyo.js?ver=

HTML / DOM Fingerprints

CSS Classes
planyo_search_fieldsplanyo_calendarplanyo_reservation_boxplanyo_availability_boxplanyo_resource_listplanyo_login_form
HTML Comments
Copyright 2015 Xtreeme GmbH (email : planyo@xtreeme.com)This program is free software; you can redistribute it and/or modifyit under the terms of the GNU General Public License as published bythe Free Software Foundation; either version 2 of the License, or+8 more
Data Attributes
planyo-site-idplanyo-languageplanyo-default-modeplanyo-resource-idplanyo-dateplanyo-calendar-height+1 more
JS Globals
planyo_objplanyo_data
Shortcode Output
[planyo[planyo plugin_path=[planyo resource_id=[planyo language=
FAQ

Frequently Asked Questions about Planyo online reservation system