Surbma | Booking.com Shortcode Security & Risk Analysis

wordpress.org/plugins/surbma-bookingcom-shortcode

A simple shortcode to include Booking.com search box into WordPress.

10 active installs v2.1.1 PHP 7.4+ WP 5.1+ Updated Apr 12, 2026
booking-comshortcode
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 13, 2026
Safety Verdict

Is Surbma | Booking.com Shortcode Safe to Use in 2026?

Generally Safe

Score 99/100

Surbma | Booking.com Shortcode has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 13, 2026Updated 6d ago
Risk Assessment

The surbma-bookingcom-shortcode plugin v2.1.1 presents a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices. There are no dangerous functions used, all SQL queries utilize prepared statements, and all identified output is properly escaped. Furthermore, the absence of file operations and external HTTP requests reduces potential attack vectors. However, a significant concern is the complete lack of nonce checks and capability checks across all entry points. While the current static analysis reports zero unprotected entry points, this is likely due to the limited scope of entry points identified (only one shortcode) and doesn't negate the inherent risk of unprotected functionality if new entry points were added or if the single shortcode's execution context could be manipulated without authentication.

The vulnerability history indicates a past medium-severity Cross-Site Scripting (XSS) vulnerability. Although there are no currently unpatched CVEs, the existence of a past XSS issue, even if resolved, suggests potential weaknesses in input sanitization or output escaping that could resurface if not carefully maintained. The fact that the last vulnerability was dated 2026-04-13 also raises a red flag, implying the data might be from a future perspective or contain an error, making it difficult to assess the current state of ongoing maintenance. The current version appears to be patched concerning past vulnerabilities, but the lack of robust authentication and authorization checks for its single entry point remains a notable weakness.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • Past medium-severity XSS vulnerability
Vulnerabilities
1

Surbma | Booking.com Shortcode Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-1607medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Surbma | Booking.com <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode

Apr 13, 2026 Patched in 2.1.1 (1d)
Version History

Surbma | Booking.com Shortcode Release Timeline

v2.1.1Current
v2.01 CVE
v1.1.01 CVE
v1.0.31 CVE
v1.0.21 CVE
Code Analysis
Analyzed Apr 16, 2026

Surbma | Booking.com Shortcode Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped1 total outputs
Attack Surface

Surbma | Booking.com Shortcode Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[surbma-bookingcom] surbma-bookingcom-shortcode.php:27
WordPress Hooks 1
actioninitsurbma-bookingcom-shortcode.php:23
Maintenance & Trust

Surbma | Booking.com Shortcode Maintenance & Trust

Maintenance Signals

WordPress version tested7.0
Last updatedApr 12, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Surbma | Booking.com Shortcode Developer Profile

Surbma

28 plugins · 30K total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
95 days
View full developer profile
Detection Fingerprints

How We Detect Surbma | Booking.com Shortcode

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
https://www.booking.com/general.html

HTML / DOM Fingerprints

Shortcode Output
<script type="text/javascript" src="
FAQ

Frequently Asked Questions about Surbma | Booking.com Shortcode