
resmio button & widget Security & Risk Analysis
wordpress.org/plugins/resmio-button-and-widgetResmio provides you with an online reservation system software for your restaurant that allows you to manage all reservations received in your restaur …
Is resmio button & widget Safe to Use in 2026?
Generally Safe
Score 85/100resmio button & widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The resmio-button-and-widget plugin version 1.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, performing all SQL queries with prepared statements, and having no known vulnerabilities or CVEs in its history. The absence of external HTTP requests and file operations further reduces the potential attack vectors. However, a significant concern arises from the output escaping. With 12 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data or data processed by the plugin that is then outputted without proper sanitization could be exploited by attackers to inject malicious scripts. The plugin also lacks nonce checks, which, while not directly tied to the observed entry points (shortcodes), is generally a good security practice for any dynamic content. The vulnerability history being empty is a positive sign but does not negate the critical nature of the unescaped output identified in the static analysis.
In conclusion, while the plugin avoids common pitfalls like raw SQL, dangerous functions, and external requests, the complete lack of output escaping presents a substantial security risk that could easily lead to XSS exploits. The absence of vulnerability history is encouraging, but the static analysis clearly points to a critical area that requires immediate attention. The security posture is therefore concerning due to this significant weakness despite other strengths.
Key Concerns
- 0% output escaping
- 0 nonce checks
resmio button & widget Security Vulnerabilities
resmio button & widget Code Analysis
Output Escaping
resmio button & widget Attack Surface
Shortcodes 2
WordPress Hooks 9
Maintenance & Trust
resmio button & widget Maintenance & Trust
Maintenance Signals
Community Trust
resmio button & widget Alternatives
Contact Form by BestWebSoft – Advanced WP Contact Form Builder for WordPress
contact-form-plugin
The most powerful and user-friendly WordPress contact form plugin. Create beautiful contact forms, widgets and pages using shortcodes.
Dropcaps Shortcode and Widget
dropcaps-shortcodes-and-widget
Create Dropcaps. Nice and easy interface. Insert anywhere in your site - page/post editor, sidebars, template files.
Quotes Shortcode and Widget
quotes-shortcode-and-widget
Create Quotes. Nice and easy interface. Insert anywhere in your site - page/post editor, sidebars, template files.
ScanCircle
scancircle
Shortcode handler for the scan widget on ScanCircle partner websites.
Button Generator
button-generator-plugin
Easy and simple create booking, shopping cart, payment plugin code, just copy and paste to your website
resmio button & widget Developer Profile
1 plugin · 400 total installs
How We Detect resmio button & widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/resmio-button-and-widget/css/resmio_backend.css/wp-content/plugins/resmio-button-and-widget/js/jquery.validate.min.js/wp-content/plugins/resmio-button-and-widget/js/additional-methods.min.js/wp-content/plugins/resmio-button-and-widget/js/jquery.xcolor.min.js/resmio-button-and-widget/js/shortcode_btns.jsresmio-button-and-widget/css/resmio_backend.css?ver=resmio-button-and-widget/js/jquery.validate.min.js?ver=resmio-button-and-widget/js/additional-methods.min.js?ver=resmio-button-and-widget/js/jquery.xcolor.min.js?ver=resmio-button-and-widget/js/shortcode_btns.js?ver=