Rezerwujestolik Security & Risk Analysis

wordpress.org/plugins/rezerwujestolik

RezerwujStolik pozwala restauracjom zarządzać rezerwacjami stolików bezpośrednio na stronie WordPress.

0 active installs v1.2.21 PHP 7.2+ WP 6.4+ Updated Mar 3, 2025
restauracjarezerwacja-stolikowrezerwacjestolikisystem-rezerwacji
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Rezerwujestolik Safe to Use in 2026?

Generally Safe

Score 92/100

Rezerwujestolik has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The 'rezerwujestolik' v1.2.21 plugin exhibits a generally strong security posture, particularly evident in its adherence to secure coding practices. The static analysis reveals no dangerous functions, all SQL queries utilize prepared statements, and an impressive 95% of output is properly escaped. Furthermore, the plugin demonstrates good security hygiene with a single nonce check and no critical or high severity taint flows. The absence of any historical vulnerabilities further reinforces this positive outlook, suggesting a mature and well-maintained codebase.

However, a key area for concern lies in the lack of capability checks on any of its entry points. While the plugin has a limited attack surface with no unprotected entry points identified in the static analysis, the absence of explicit capability checks for AJAX handlers and shortcodes means that any authenticated user, regardless of their role or permissions, could potentially trigger plugin functionalities. This could lead to unauthorized actions or information disclosure if specific actions are sensitive. The single external HTTP request, while not inherently risky, warrants attention to ensure its destination and purpose are legitimate and secure.

In conclusion, 'rezerwujestolik' v1.2.21 is a well-coded plugin with a clear commitment to security. Its strong foundation in prepared statements and output escaping is commendable. The primary weakness is the oversight in implementing capability checks, which, while not currently exploited, represents a potential security gap. Addressing this would significantly enhance the plugin's overall security and provide a more robust defense against potential misuse.

Key Concerns

  • Missing capability checks on entry points
  • One external HTTP request without context
Vulnerabilities
None known

Rezerwujestolik Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Rezerwujestolik Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
60 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

95% escaped63 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
rezerwujestolik_process_places (rezerwujestolik.php:171)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Rezerwujestolik Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 1

authwp_ajax_rezerwujestolik_process_placesrezerwujestolik.php:168

Shortcodes 2

[rezerwujestolik_button] rezerwujestolik.php:231
[rezerwujestolik_widget] rezerwujestolik.php:246
WordPress Hooks 13
actionadmin_menurezerwujestolik.php:52
actionadmin_initrezerwujestolik.php:57
actionsend_headersrezerwujestolik.php:66
actionsend_headersrezerwujestolik.php:68
actionwp_enqueue_scriptsrezerwujestolik.php:119
actionadmin_headrezerwujestolik.php:129
actionwp_enqueue_scriptsrezerwujestolik.php:141
actionadmin_enqueue_scriptsrezerwujestolik.php:165
actionwp_footerrezerwujestolik.php:280
actionadmin_footerrezerwujestolik.php:282
actionadmin_initrezerwujestolik.php:288
actionupdated_optionrezerwujestolik.php:289
actionadmin_noticesrezerwujestolik.php:329
Maintenance & Trust

Rezerwujestolik Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 3, 2025
PHP min version7.2
Downloads455

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Rezerwujestolik Developer Profile

RezerwujeStolik

1 plugin · 0 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Rezerwujestolik

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/rezerwujestolik/css/style.css/wp-content/plugins/rezerwujestolik/css/admin-style.css/wp-content/plugins/rezerwujestolik/js/modal.js/wp-content/plugins/rezerwujestolik/js/admin-scripts.js
Script Paths
https://rezerwujestolik.pl/assets/reservation-form.jshttps://rezerwujestolik.pl/assets/reservation-form.css
Version Parameters
rezerwujestolik/css/style.css?ver=rezerwujestolik/css/admin-style.css?ver=rezerwujestolik/js/modal.js?ver=rezerwujestolik/js/admin-scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
rezerwujestolik-button
Data Attributes
data-rezerwujestolik-url
JS Globals
places_ajax_object
REST Endpoints
/wp-json/rezerwujestolik
Shortcode Output
<button class="rezerwujestolik-button" style="
FAQ

Frequently Asked Questions about Rezerwujestolik