resmio button & widget Security & Risk Analysis

wordpress.org/plugins/resmio-button-and-widget

Resmio provides you with an online reservation system software for your restaurant that allows you to manage all reservations received in your restaur …

400 active installs v1.3 PHP + WP + Updated Dec 14, 2021
buttonresmioshortcodeusabilitywidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is resmio button & widget Safe to Use in 2026?

Generally Safe

Score 85/100

resmio button & widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The resmio-button-and-widget plugin version 1.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, performing all SQL queries with prepared statements, and having no known vulnerabilities or CVEs in its history. The absence of external HTTP requests and file operations further reduces the potential attack vectors. However, a significant concern arises from the output escaping. With 12 total outputs and 0% properly escaped, this indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data or data processed by the plugin that is then outputted without proper sanitization could be exploited by attackers to inject malicious scripts. The plugin also lacks nonce checks, which, while not directly tied to the observed entry points (shortcodes), is generally a good security practice for any dynamic content. The vulnerability history being empty is a positive sign but does not negate the critical nature of the unescaped output identified in the static analysis.

In conclusion, while the plugin avoids common pitfalls like raw SQL, dangerous functions, and external requests, the complete lack of output escaping presents a substantial security risk that could easily lead to XSS exploits. The absence of vulnerability history is encouraging, but the static analysis clearly points to a critical area that requires immediate attention. The security posture is therefore concerning due to this significant weakness despite other strengths.

Key Concerns

  • 0% output escaping
  • 0 nonce checks
Vulnerabilities
None known

resmio button & widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

resmio button & widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
0 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped12 total outputs
Attack Surface

resmio button & widget Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[resmio-button] resmio-btn-wdgt.php:45
[resmio-widget] resmio-btn-wdgt.php:46
WordPress Hooks 9
actionadmin_initresmio-btn-wdgt.php:43
actionadmin_menuresmio-btn-wdgt.php:44
filterwidget_textresmio-btn-wdgt.php:48
actionadmin_enqueue_scriptsresmio-btn-wdgt.php:49
actionwp_enqueue_scriptsresmio-btn-wdgt.php:50
filtermce_external_pluginsresmio-btn-wdgt.php:175
filtermce_buttonsresmio-btn-wdgt.php:176
actionadmin_headresmio-btn-wdgt.php:179
actionadmin_enqueue_scriptstemplates\settings.php:2
Maintenance & Trust

resmio button & widget Maintenance & Trust

Maintenance Signals

WordPress version tested5.8.13
Last updatedDec 14, 2021
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings3
Active installs400
Developer Profile

resmio button & widget Developer Profile

Philipp-resmio

1 plugin · 400 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect resmio button & widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/resmio-button-and-widget/css/resmio_backend.css/wp-content/plugins/resmio-button-and-widget/js/jquery.validate.min.js/wp-content/plugins/resmio-button-and-widget/js/additional-methods.min.js/wp-content/plugins/resmio-button-and-widget/js/jquery.xcolor.min.js
Script Paths
/resmio-button-and-widget/js/shortcode_btns.js
Version Parameters
resmio-button-and-widget/css/resmio_backend.css?ver=resmio-button-and-widget/js/jquery.validate.min.js?ver=resmio-button-and-widget/js/additional-methods.min.js?ver=resmio-button-and-widget/js/jquery.xcolor.min.js?ver=resmio-button-and-widget/js/shortcode_btns.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about resmio button & widget