Shore Booking Widget Security & Risk Analysis

wordpress.org/plugins/shore-booking-widget

Integrate Shore's booking system into your WordPress site with embedded booking, standard button, or floating button display options.

40 active installs v1.0.4 PHP 7.4+ WP 5.0+ Updated Mar 6, 2026
appointmentsbookingschedulingshorewidgets
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Shore Booking Widget Safe to Use in 2026?

Generally Safe

Score 100/100

Shore Booking Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 29d ago
Risk Assessment

The "shore-booking-widget" plugin version 1.0.5 exhibits a generally good security posture based on the static analysis. It has no recorded vulnerabilities in its history, which is a significant positive. The absence of dangerous functions, SQL queries without prepared statements, file operations, and external HTTP requests are all strong indicators of secure coding practices. Furthermore, the plugin implements nonce and capability checks on its entry points, which helps to mitigate common attack vectors.

Key Concerns

  • Output escaping is only 55% proper
Vulnerabilities
None known

Shore Booking Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Shore Booking Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
65
81 escaped
Nonce Checks
2
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

55% escaped146 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
shbw_save_token_ajax (shore-booking-widget.php:862)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Shore Booking Widget Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_shbw_dismiss_welcomeshore-booking-widget.php:857
authwp_ajax_shbw_save_tokenshore-booking-widget.php:893

Shortcodes 1

[shore_booking] shore-booking-widget.php:51
WordPress Hooks 7
actionplugins_loadedshore-booking-widget.php:48
actionadmin_menushore-booking-widget.php:49
actionadmin_initshore-booking-widget.php:50
actionadmin_enqueue_scriptsshore-booking-widget.php:100
actionadmin_enqueue_scriptsshore-booking-widget.php:732
actionadmin_noticesshore-booking-widget.php:842
actionupdate_option_shbw_config_tokenshore-booking-widget.php:904
Maintenance & Trust

Shore Booking Widget Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 6, 2026
PHP min version7.4
Downloads442

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Shore Booking Widget Developer Profile

shoregmbh

1 plugin · 40 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Shore Booking Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/shore-booking-widget/assets/admin.css/wp-content/plugins/shore-booking-widget/assets/admin.js
Script Paths
https://connect.shore.com/widget/loading.jshttps://connect.shore.com/widget/booking.js
Version Parameters
shore-booking-widget/assets/admin.css?ver=shore-booking-widget/assets/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
termine24-widgettermine24-widget-custom
Data Attributes
data-companydata-localedata-theme-colordata-text-colordata-textdata-select-location
JS Globals
shoreBookingSettings
Shortcode Output
<a class="termine24-widget<div id="shore-booking-widget-root"
FAQ

Frequently Asked Questions about Shore Booking Widget