
Surbma | Booking.com Shortcode Security & Risk Analysis
wordpress.org/plugins/surbma-bookingcom-shortcodeA simple shortcode to include Booking.com search box into WordPress.
Is Surbma | Booking.com Shortcode Safe to Use in 2026?
Generally Safe
Score 99/100Surbma | Booking.com Shortcode has a strong security track record. Known vulnerabilities have been patched promptly.
The surbma-bookingcom-shortcode plugin v2.1.1 presents a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices. There are no dangerous functions used, all SQL queries utilize prepared statements, and all identified output is properly escaped. Furthermore, the absence of file operations and external HTTP requests reduces potential attack vectors. However, a significant concern is the complete lack of nonce checks and capability checks across all entry points. While the current static analysis reports zero unprotected entry points, this is likely due to the limited scope of entry points identified (only one shortcode) and doesn't negate the inherent risk of unprotected functionality if new entry points were added or if the single shortcode's execution context could be manipulated without authentication.
The vulnerability history indicates a past medium-severity Cross-Site Scripting (XSS) vulnerability. Although there are no currently unpatched CVEs, the existence of a past XSS issue, even if resolved, suggests potential weaknesses in input sanitization or output escaping that could resurface if not carefully maintained. The fact that the last vulnerability was dated 2026-04-13 also raises a red flag, implying the data might be from a future perspective or contain an error, making it difficult to assess the current state of ongoing maintenance. The current version appears to be patched concerning past vulnerabilities, but the lack of robust authentication and authorization checks for its single entry point remains a notable weakness.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Past medium-severity XSS vulnerability
Surbma | Booking.com Shortcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Surbma | Booking.com <= 2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Surbma | Booking.com Shortcode Release Timeline
Surbma | Booking.com Shortcode Code Analysis
Output Escaping
Surbma | Booking.com Shortcode Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
Surbma | Booking.com Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Surbma | Booking.com Shortcode Alternatives
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
Surbma | Booking.com Shortcode Developer Profile
28 plugins · 30K total installs
How We Detect Surbma | Booking.com Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
https://www.booking.com/general.htmlHTML / DOM Fingerprints
<script type="text/javascript" src="