Sofcar for WP Security & Risk Analysis

wordpress.org/plugins/sofcar-for-wp

Sofcar is a customizable car rental booking engine with online payment gateways, automatic email notifications, fully compatible with all WordPress Th …

10 active installs v1.0.1 PHP 7.0+ WP 3.6.1+ Updated Jan 9, 2021
car-rental-softwarefree-fleet-managementonlien-booking-enginerent-a-carsofcar
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sofcar for WP Safe to Use in 2026?

Generally Safe

Score 85/100

Sofcar for WP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The "sofcar-for-wp" v1.0.1 plugin exhibits a mixed security posture. On the positive side, there are no known historical vulnerabilities (CVEs), which is an excellent sign. The code also demonstrates good practices by exclusively using prepared statements for SQL queries and avoiding dangerous functions. The attack surface appears well-managed with zero unprotected entry points.

However, several areas raise concerns. The significant percentage of improperly escaped output (39%) is a notable weakness. Coupled with two taint flows involving unsanitized paths, this could potentially lead to cross-site scripting (XSS) vulnerabilities if user-supplied data reaches these unsanitized paths and is then outputted without proper escaping. The absence of nonce checks for any entry points, while not directly identified as a vulnerability here due to the lack of unprotected AJAX/REST endpoints, is generally a weak practice that should be addressed for robust security.

In conclusion, while the plugin benefits from a clean vulnerability history and strong SQL practices, the high rate of unescaped output and the presence of unsanitized path flows warrant careful consideration. Addressing these specific code-level issues will significantly improve the plugin's overall security.

Key Concerns

  • High percentage of unescaped output
  • Taint flows with unsanitized paths
  • No nonce checks on entry points
Vulnerabilities
None known

Sofcar for WP Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Sofcar for WP Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
160
247 escaped
Nonce Checks
0
Capability Checks
1
File Operations
6
External Requests
1
Bundled Libraries
0

Output Escaping

61% escaped407 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
save_token (admin\class-sofcar-api.php:159)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Sofcar for WP Attack Surface

Entry Points5
Unprotected0

Shortcodes 5

[sofcar-searcher] public\inc\sofcar-shortcode.php:14
[sofcar-fleet] public\inc\sofcar-shortcode.php:16
[sofcar-contact] public\inc\sofcar-shortcode.php:18
[sofcar-vehicle] public\inc\sofcar-shortcode.php:20
[sofcar-account] public\inc\sofcar-shortcode.php:22
WordPress Hooks 8
actionplugins_loadedincludes\class-sofcar.php:129
actionadmin_enqueue_scriptsincludes\class-sofcar.php:144
actionadmin_enqueue_scriptsincludes\class-sofcar.php:146
actionadmin_menuincludes\class-sofcar.php:148
actionadmin_bar_menuincludes\class-sofcar.php:150
actionwp_enqueue_scriptsincludes\class-sofcar.php:165
actionwp_enqueue_scriptsincludes\class-sofcar.php:167
actioninitpublic\inc\sofcar-shortcode.php:26
Maintenance & Trust

Sofcar for WP Maintenance & Trust

Maintenance Signals

WordPress version tested5.6.17
Last updatedJan 9, 2021
PHP min version7.0
Downloads3K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

Sofcar for WP Developer Profile

SofcarTeam

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sofcar for WP

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sofcar-for-wp/css/sofcar-admin.css/wp-content/plugins/sofcar-for-wp/js/sofcar-admin.js
Script Paths
js/sofcar-admin.js
Version Parameters
sofcar-admin.css?ver=sofcar-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
sofcar-top-bar-menu-item
Data Attributes
data-tabdata-type
FAQ

Frequently Asked Questions about Sofcar for WP