SuperSaaS – online appointment scheduling Security & Risk Analysis

wordpress.org/plugins/supersaas-appointment-scheduling

SuperSaaS is a flexible appointment scheduling system that works with many different businesses. The basic version is free.

1K active installs v2.1.15 PHP + WP 2.7+ Updated Dec 3, 2025
appointment-schedulingappointmentsbooking-calendarmeetingsreservations
99
A · Safe
CVEs total2
Unpatched0
Last CVEFeb 10, 2025
Safety Verdict

Is SuperSaaS – online appointment scheduling Safe to Use in 2026?

Generally Safe

Score 99/100

SuperSaaS – online appointment scheduling has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Feb 10, 2025Updated 5mo ago
Risk Assessment

The supersaas-appointment-scheduling plugin v2.1.15 exhibits a mixed security posture. On the positive side, the static analysis reveals a limited attack surface with no unprotected entry points, no dangerous functions, and all SQL queries utilizing prepared statements. Furthermore, the plugin demonstrates a capability check, indicating some level of access control is in place.

However, significant concerns arise from the output escaping. The analysis shows that 100% of the 6 identified outputs are not properly escaped, representing a clear Cross-Site Scripting (XSS) risk. Despite the absence of critical or high-severity taint flows in this specific analysis, the historical vulnerability data reveals a pattern of medium-severity XSS vulnerabilities. The fact that the last recorded vulnerability was in February 2025, and there are no currently unpatched CVEs, suggests the developers are addressing issues, but the recurring nature of XSS is a persistent concern.

In conclusion, while the plugin has strengths in its SQL handling and limited attack surface, the lack of output escaping and the historical prevalence of XSS vulnerabilities present a notable risk. Users should be aware of the potential for XSS attacks, especially if the plugin is used in conjunction with other less secure components or if user-supplied data is directly reflected in the output.

Key Concerns

  • Outputs are not properly escaped
  • Historical medium severity XSS vulnerabilities
  • No nonce checks on entry points
Vulnerabilities
2 published

SuperSaaS – online appointment scheduling Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-0862medium · 4.9Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SuperSaaS – online appointment scheduling <= 2.1.12 - Authenticated (Contributor+) Stored Cross-Site Scripting via after Parameter

Feb 10, 2025 Patched in 2.1.13 (1d)
CVE-2024-37460medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

SuperSaaS – online appointment scheduling <= 2.1.9 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jul 1, 2024 Patched in 2.1.10 (9d)
Code Analysis
Analyzed Mar 16, 2026

SuperSaaS – online appointment scheduling Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Attack Surface

SuperSaaS – online appointment scheduling Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[supersaas] supersaas.php:61
WordPress Hooks 3
actionadmin_menusupersaas.php:66
actionadmin_enqueue_scriptssupersaas.php:67
actionadmin_initsupersaas.php:68
Maintenance & Trust

SuperSaaS – online appointment scheduling Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version
Downloads48K

Community Trust

Rating68/100
Number of ratings10
Active installs1K
Developer Profile

SuperSaaS – online appointment scheduling Developer Profile

supersaas

1 plugin · 1K total installs

99
trust score
Avg Security Score
99/100
Avg Patch Time
5 days
View full developer profile
Detection Fingerprints

How We Detect SuperSaaS – online appointment scheduling

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/supersaas-appointment-scheduling/includes/js/admin.js

HTML / DOM Fingerprints

CSS Classes
tog
Data Attributes
name="ss_account_name"name="ss_display_choice"name="ss_autologin_enabled"name="ss_password"name="ss_widget_script"name="ss_schedule"+4 more
FAQ

Frequently Asked Questions about SuperSaaS – online appointment scheduling