
SuperSaaS – online appointment scheduling Security & Risk Analysis
wordpress.org/plugins/supersaas-appointment-schedulingSuperSaaS is a flexible appointment scheduling system that works with many different businesses. The basic version is free.
Is SuperSaaS – online appointment scheduling Safe to Use in 2026?
Generally Safe
Score 99/100SuperSaaS – online appointment scheduling has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The supersaas-appointment-scheduling plugin v2.1.15 exhibits a mixed security posture. On the positive side, the static analysis reveals a limited attack surface with no unprotected entry points, no dangerous functions, and all SQL queries utilizing prepared statements. Furthermore, the plugin demonstrates a capability check, indicating some level of access control is in place.
However, significant concerns arise from the output escaping. The analysis shows that 100% of the 6 identified outputs are not properly escaped, representing a clear Cross-Site Scripting (XSS) risk. Despite the absence of critical or high-severity taint flows in this specific analysis, the historical vulnerability data reveals a pattern of medium-severity XSS vulnerabilities. The fact that the last recorded vulnerability was in February 2025, and there are no currently unpatched CVEs, suggests the developers are addressing issues, but the recurring nature of XSS is a persistent concern.
In conclusion, while the plugin has strengths in its SQL handling and limited attack surface, the lack of output escaping and the historical prevalence of XSS vulnerabilities present a notable risk. Users should be aware of the potential for XSS attacks, especially if the plugin is used in conjunction with other less secure components or if user-supplied data is directly reflected in the output.
Key Concerns
- Outputs are not properly escaped
- Historical medium severity XSS vulnerabilities
- No nonce checks on entry points
SuperSaaS – online appointment scheduling Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
SuperSaaS – online appointment scheduling <= 2.1.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via after Parameter
SuperSaaS – online appointment scheduling <= 2.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
SuperSaaS – online appointment scheduling Release Timeline
SuperSaaS – online appointment scheduling Code Analysis
Output Escaping
SuperSaaS – online appointment scheduling Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
SuperSaaS – online appointment scheduling Maintenance & Trust
Maintenance Signals
Community Trust
SuperSaaS – online appointment scheduling Alternatives
Pinpoint Booking System – Version 2
booking-system
Book anything, anytime, anywhere.
VikAppointments Services Booking Calendar
vikappointments
A reliable tool for managing any kind of appointments, scheduling the bookings of various services, and organizing the calendars of several employees.
Ultimate Appointment Booking & Scheduling
ultimate-appointment-scheduling
Appointment booking calendar and scheduling plugin that lets you set up different services, service providers, locations and availability
Nemtly Booking – Events, Appointments & Booking Calendar
nemtly-booking
Book appointments and events 24/7 with Stripe payments, Google Calendar sync, reminders, and a customer dashboard. Blocks and shortcodes included.
Online Scheduling and Appointment Booking System – Bookly
bookly-responsive-appointment-booking-tool
Appointment booking system for WordPress — schedule appointments, manage calendars, send reminders, take payments. Start booking today!
SuperSaaS – online appointment scheduling Developer Profile
1 plugin · 1K total installs
How We Detect SuperSaaS – online appointment scheduling
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/supersaas-appointment-scheduling/includes/js/admin.jsHTML / DOM Fingerprints
togname="ss_account_name"name="ss_display_choice"name="ss_autologin_enabled"name="ss_password"name="ss_widget_script"name="ss_schedule"+4 more