
Rezgo Online Booking Security & Risk Analysis
wordpress.org/plugins/rezgoSell your tours, activities, and events on your WordPress website using Rezgo.
Is Rezgo Online Booking Safe to Use in 2026?
Generally Safe
Score 96/100Rezgo Online Booking has a strong security track record. Known vulnerabilities have been patched promptly.
The "rezgo" v4.22 plugin exhibits a mixed security posture, with some positive security practices alongside significant areas of concern. While the plugin demonstrates a high rate of output escaping (92%) and a reasonable number of nonce checks, the presence of unprotected AJAX handlers and a lack of preparedness for SQL queries are notable weaknesses. The static analysis reveals critical risks related to unsanitized paths in taint flows, indicating potential for attackers to manipulate file operations or inject malicious code. The 4 identified dangerous functions, specifically "unserialize," further amplify these risks, as unserialized data from untrusted sources can lead to arbitrary code execution.
The plugin's vulnerability history shows a pattern of past security flaws, particularly concerning Remote File Inclusion and Cross-site Scripting. Although there are currently no unpatched CVEs, the existence of a high-severity unpatched vulnerability in the past, along with past medium-severity issues, suggests a recurring need for diligent security patching and code review. The fact that the last vulnerability was in 2025-01-06, despite it being a past vulnerability, is a curious detail but doesn't negate the historical pattern. Overall, the plugin has strengths in output handling but requires immediate attention to its insecure entry points, data sanitization, and historical vulnerability trends.
Key Concerns
- Unprotected AJAX handlers
- SQL queries without prepared statements
- High severity taint flows
- Use of unserialize function
- Past high severity unpatched vulnerability
- Past medium severity vulnerabilities
- Unsanitized paths in taint analysis
Rezgo Online Booking Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Rezgo Online Booking <= 4.17 - Unauthenticated Local File Inclusion
Rezgo Online Booking <= 4.1.7 - Reflected Cross-Site-Scripting
Rezgo Online Booking < 1.8.2 - Cross-Site Scripting
Rezgo Online Booking < 1.4.3 - Cross-Site Scripting
Rezgo Online Booking Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Rezgo Online Booking Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 23
Maintenance & Trust
Rezgo Online Booking Maintenance & Trust
Maintenance Signals
Community Trust
Rezgo Online Booking Alternatives
Understory
understory
Connect your Understory account with WordPress, to easily add Booking and Experience Widgets to your pages!
indexic aReservation
indexic-areservation
Easily integrate Indexic's aReservation Tour Booking and Rental Reservation Software into your WordPress website. You can add booking buttons wi …
SimplyBook.me – Booking and reservations calendar
simplybook
Simply add a booking calendar to your site to schedule bookings, reservations, appointments and to collect payments.
BA Book Everything
ba-book-everything
The really fast and powerful Booking engine for theme/site developers to create any booking or rental sites (tours, cars, events, apartments, yachts)
FareHarbor for WordPress
fareharbor
Easily add FareHarbor reservation calendars, booking embeds, and buttons to your site.
Rezgo Online Booking Developer Profile
1 plugin · 200 total installs
How We Detect Rezgo Online Booking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.