Servv AI Event Booking Security & Risk Analysis

wordpress.org/plugins/servvai-event-booking

Servv AI Event Booking helps you create events with AI, Zoom integration, ticketing, and reminders all in one place. You can add events to any post on …

0 active installs v1.0.29 PHP + WP 6.0+ Updated Apr 15, 2026
booking-systemevent-bookingevent-calendaronline-bookingwordpress-events-plugin
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Servv AI Event Booking Safe to Use in 2026?

Generally Safe

Score 100/100

Servv AI Event Booking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The servvai-event-booking plugin v1.0.27 exhibits a generally strong security posture based on the static analysis. It demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output, which are crucial for preventing common web vulnerabilities. The presence of a significant number of nonce checks and capability checks also indicates an effort to secure its entry points. The plugin does not appear to have any publicly known vulnerabilities (CVEs), which is a positive indicator of its historical security. However, a notable concern arises from the taint analysis, which found 10 flows with unsanitized paths. While these did not result in critical or high severity findings, the presence of 100% of analyzed flows with unsanitized paths is a significant red flag and suggests a potential for vulnerabilities if inputs are not rigorously validated and sanitized within the plugin's logic. The plugin also has a moderate attack surface with 27 entry points, all of which appear to have authorization checks, which is positive, but the taint analysis necessitates careful review of how these entry points handle user-supplied data.

Key Concerns

  • Unsanitized paths in taint analysis (10 flows)
  • Bundled library (Lodash)
Vulnerabilities
None known

Servv AI Event Booking Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Servv AI Event Booking Release Timeline

v1.0.29Current
v1.0.28
v1.0.27
v1.0.26
v1.0.25
v1.0.24
v1.0.23
v1.0.22
v1.0.21
v1.0.20
v1.0.19
v1.0.18
v1.0.17
v1.0.16
v1.0.15
v1.0.14
v1.0.13
v1.0.12
v1.0.11
v1.0.10
Code Analysis
Analyzed Mar 17, 2026

Servv AI Event Booking Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
101 escaped
Nonce Checks
15
Capability Checks
4
File Operations
6
External Requests
3
Bundled Libraries
1

Bundled Libraries

Lodash

Output Escaping

100% escaped101 total outputs
Data Flows · Security
10 unsanitized

Data Flow Analysis

10 flows10 with unsanitized paths
servv_plugin_zoom_confirm (inc\api.php:372)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Servv AI Event Booking Attack Surface

Entry Points27
Unprotected0

AJAX Handlers 24

authwp_ajax_servv_create_payment_intentinc\orders.php:7
noprivwp_ajax_servv_create_payment_intentinc\orders.php:8
authwp_ajax_servv_create_checkout_sessioninc\orders.php:9
noprivwp_ajax_servv_create_checkout_sessioninc\orders.php:10
authwp_ajax_servv_process_free_orderinc\orders.php:11
authwp_ajax_servv_process_free_orderinc\orders.php:12
authwp_ajax_servv_get_event_infoinc\orders.php:13
noprivwp_ajax_servv_get_event_infoinc\orders.php:14
authwp_ajax_servv_get_types_listinc\orders.php:15
noprivwp_ajax_servv_get_types_listinc\orders.php:16
authwp_ajax_servv_get_event_questions_listinc\orders.php:17
noprivwp_ajax_servv_get_event_questions_listinc\orders.php:18
authwp_ajax_servv_add_event_answerinc\orders.php:19
noprivwp_ajax_servv_add_event_answerinc\orders.php:20
authwp_ajax_servv_add_to_waitinglistinc\orders.php:21
noprivwp_ajax_servv_add_to_waitinglistinc\orders.php:22
authwp_ajax_servv_get_events_filtered_list_datesinc\orders.php:23
noprivwp_ajax_servv_get_events_filtered_list_datesinc\orders.php:24
authwp_ajax_servv_get_events_filtered_listinc\orders.php:25
noprivwp_ajax_servv_get_events_filtered_listinc\orders.php:26
authwp_ajax_servv_get_shop_settingsinc\orders.php:27
noprivwp_ajax_servv_get_shop_settingsinc\orders.php:28
authwp_ajax_servv_get_shop_settingsservv.php:333
noprivwp_ajax_servv_get_shop_settingsservv.php:334

Shortcodes 3

[servv_event_purchase_form] servv.php:267
[servvai] servv.php:468
[servvplatformwidget] servv.php:882
WordPress Hooks 29
actionrest_api_initinc\ajax\analytics\routes.php:7
actionrest_api_initinc\ajax\calendar\routes.php:7
actionrest_api_initinc\ajax\events\bookings\routes.php:7
actionrest_api_initinc\ajax\events\qa\routes.php:7
actionrest_api_initinc\ajax\events\routes.php:11
actionrest_api_initinc\ajax\events\tickets\routes.php:7
actionrest_api_initinc\ajax\filters\categories\routes.php:7
actionrest_api_initinc\ajax\filters\languages\routes.php:7
actionrest_api_initinc\ajax\filters\locations\routes.php:7
actionrest_api_initinc\ajax\filters\members\routes.php:7
actionrest_api_initinc\ajax\filters\teams\routes.php:7
actionrest_api_initinc\ajax\gmail\routes.php:7
actionrest_api_initinc\ajax\shop\routes.php:7
actionrest_api_initinc\ajax\stripe\routes.php:7
actionrest_api_initinc\ajax\zoom\routes.php:7
actionsave_postinc\api.php:14
actionbefore_delete_postinc\api.php:15
actionrest_api_initinc\orders.php:31
actionservv_plugin_delayed_installservv.php:24
actionrest_api_initservv.php:25
actionwpmu_new_blogservv.php:83
actioninitservv.php:189
actionwp_enqueue_scriptsservv.php:195
actionwp_enqueue_scriptsservv.php:211
filterthe_contentservv.php:266
actionadmin_menuservv.php:292
actionadmin_enqueue_scriptsservv.php:293
actionwp_headservv.php:374
actionwp_enqueue_scriptsservv.php:467

Scheduled Events 2

servv_plugin_delayed_install
servv_plugin_delayed_install
Maintenance & Trust

Servv AI Event Booking Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 15, 2026
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings1
Active installs0
Developer Profile

Servv AI Event Booking Developer Profile

Servv AI Event Booking

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Servv AI Event Booking

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/servvai-event-booking/build-assets/index.css/wp-content/plugins/servvai-event-booking/build/checkout.js/wp-content/plugins/servvai-event-booking/build/block.json
Script Paths
/wp-content/plugins/servvai-event-booking/build/checkout.js
Version Parameters
servvai-event-booking/build-assets/index.css?ver=servvai-event-booking/build/checkout.js?ver=

HTML / DOM Fingerprints

CSS Classes
servv-checkout-formservv-checkout-button
HTML Comments
<!-- servv_event_id --><!-- end servv_event_id --><!-- servv_event_start_date --><!-- end servv_event_start_date -->+4 more
Data Attributes
data-servv-post-iddata-servv-event-id
JS Globals
servvDataservvCheckoutData
REST Endpoints
/wp-json/servvai-event-booking/v1/check-signature/wp-json/servvai-event-booking/v1/variant-info
Shortcode Output
[servv_event_booking][servv_event_details event_id=][servv_event_checkout event_id=]
FAQ

Frequently Asked Questions about Servv AI Event Booking