
Widgets for Booking.com Reviews Security & Risk Analysis
wordpress.org/plugins/review-widgets-for-booking-comEmbed Booking.com reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Booking.com reviews.
Is Widgets for Booking.com Reviews Safe to Use in 2026?
Generally Safe
Score 100/100Widgets for Booking.com Reviews has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "review-widgets-for-booking-com" plugin v13.2.7 exhibits a mixed security posture. On the positive side, the plugin demonstrates strong adherence to best practices regarding SQL queries, with 98% using prepared statements, and all output appears to be properly escaped. The significant number of nonce and capability checks also suggests an awareness of security principles. However, there are notable areas of concern stemming from its attack surface. All three identified entry points (AJAX handlers and REST API routes) lack adequate authentication or permission checks, presenting a significant risk of unauthorized access and potential manipulation.
The static analysis also flags a dangerous function, `unserialize`, which, when combined with unprotected entry points, could lead to serious vulnerabilities if unsanitized user input is ever passed to it. While the taint analysis did not uncover critical or high-severity issues, the presence of a flow with unsanitized paths, even if not classified as critical, warrants attention, especially given the `unserialize` function. The plugin's vulnerability history is currently clean, with no known CVEs, which is a positive indicator of its past security. Nevertheless, the current static analysis findings point to inherent weaknesses that could be exploited, particularly the unprotected entry points.
Key Concerns
- All entry points lack authentication checks
- Unprotected REST API routes
- Unprotected AJAX handlers
- Use of dangerous 'unserialize' function
- Flow with unsanitized paths
Widgets for Booking.com Reviews Security Vulnerabilities
Widgets for Booking.com Reviews Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Widgets for Booking.com Reviews Attack Surface
AJAX Handlers 1
REST API Routes 2
WordPress Hooks 36
Maintenance & Trust
Widgets for Booking.com Reviews Maintenance & Trust
Maintenance Signals
Community Trust
Widgets for Booking.com Reviews Alternatives
Review Manager
review-manager
The Review Manager® WordPress plugin extends the functionality of the SaaS Review Manager® to WordPress so that the review feed can be displayed on th …
Fleek Reviews for Google Business
fleek-reviews-for-google-business
Display Google Business Reviews on your WordPress site with customizable layouts, caching, and zero coding required.
Widgets for Google Reviews
wp-reviews-plugin-for-google
Embed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
SiteOrigin Widgets Bundle
so-widgets-bundle
Essential elements for modern websites. Add buttons, sliders, heroes, maps, images, carousels, features, icons, more. Create dynamic pages easily.
Rich Showcase for Google Reviews
widget-google-reviews
Display up to 10 Google reviews in less than a minute. Continue collecting new reviews. No limits on connected places, widgets, shortcodes and blocks.
Widgets for Booking.com Reviews Developer Profile
32 plugins · 976K total installs
How We Detect Widgets for Booking.com Reviews
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/review-widgets-for-booking-com/css/ti-widgets.css/wp-content/plugins/review-widgets-for-booking-com/js/ti-widgets.jshttps://cdn.trustindex.io/loader.jsreview-widgets-for-booking-com/css/ti-widgets.css?ver=review-widgets-for-booking-com/js/ti-widgets.js?ver=HTML / DOM Fingerprints
ti-widgets-containerti-reviews-sliderti-review-item<!-- Trust index widget --><!-- Trustindex.io -->data-ti-widget-iddata-ti-booking-iddata-ti-widget-typetrustindex_booking_params/wp-json/trustindex/v1/getReviews[bookingreviews]