TimeTailor Salon Booking Security & Risk Analysis

wordpress.org/plugins/timetailor-salon-booking

Professional salon booking software for WordPress. Accept online bookings, manage salon appointments, and embed the TimeTailor salon booking widget.

0 active installs v1.0.0 PHP 7.4+ WP 6.0+ Updated Apr 15, 2026
salon-booking-softwaresalon-booking-widgetsalon-management-softwaresalon-softwarewordpress-booking
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is TimeTailor Salon Booking Safe to Use in 2026?

Generally Safe

Score 100/100

TimeTailor Salon Booking has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "timetailor-salon-booking" plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. All identified AJAX handlers implement authentication checks, and there are no REST API routes, shortcodes, or cron events that could serve as additional entry points without proper authorization. The code follows secure coding practices with 100% of SQL queries using prepared statements and 100% of output properly escaped. The absence of dangerous functions and a lack of critical or high severity taint analysis flows further reinforce its secure design. Nonce checks are present on most entry points, and capability checks are also implemented.

However, a small concern arises from the presence of one file operation and five external HTTP requests, which, while not inherently vulnerable, represent potential vectors for attack if not handled with extreme care or if external services are compromised. The vulnerability history is completely clean, indicating a lack of past security issues and suggesting consistent attention to security by the developers, or that the plugin is relatively new and has not yet encountered discovered vulnerabilities. Overall, the plugin appears to be well-secured with a robust implementation of standard WordPress security practices.

Key Concerns

  • File operations present
  • External HTTP requests present
Vulnerabilities
None known

TimeTailor Salon Booking Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

TimeTailor Salon Booking Release Timeline

v1.0.0Current
Code Analysis
Analyzed Apr 16, 2026

TimeTailor Salon Booking Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
68 escaped
Nonce Checks
7
Capability Checks
1
File Operations
1
External Requests
5
Bundled Libraries
0

Output Escaping

100% escaped68 total outputs
Attack Surface

TimeTailor Salon Booking Attack Surface

Entry Points9
Unprotected0

AJAX Handlers 9

noprivwp_ajax_ttsbs_loginincludes/class-ttsbs-ajax-handlers.php:8
authwp_ajax_ttsbs_loginincludes/class-ttsbs-ajax-handlers.php:9
noprivwp_ajax_ttsbs_signupincludes/class-ttsbs-ajax-handlers.php:11
authwp_ajax_ttsbs_signupincludes/class-ttsbs-ajax-handlers.php:12
authwp_ajax_ttsbs_get_user_auth_linkincludes/class-ttsbs-ajax-handlers.php:14
authwp_ajax_ttsbs_get_location_auth_linkincludes/class-ttsbs-ajax-handlers.php:15
authwp_ajax_ttsbs_save_preferred_locationincludes/class-ttsbs-ajax-handlers.php:17
authwp_ajax_ttsbs_logoutincludes/class-ttsbs-ajax-handlers.php:19
authwp_ajax_ttsbs_invite_location_ownerincludes/class-ttsbs-ajax-handlers.php:21
WordPress Hooks 10
actionadmin_menuincludes/admin/class-ttsbs-admin-menu.php:9
actionadmin_menuincludes/admin/class-ttsbs-admin-menu.php:10
actionload-toplevel_page_timetailor-salon-bookingincludes/admin/class-ttsbs-admin-menu.php:12
actionadmin_page_access_deniedincludes/admin/class-ttsbs-admin-menu.php:14
actionadmin_enqueue_scriptsincludes/class-ttsbs-salon-booking-software.php:70
actionadmin_initincludes/class-ttsbs-salon-booking-software.php:72
actionadmin_initincludes/class-ttsbs-salon-booking-software.php:74
filteradmin_footer_textincludes/class-ttsbs-salon-booking-software.php:76
actionplugins_loadedtimetailor-salon-booking.php:26
actioninittimetailor-salon-booking.php:27
Maintenance & Trust

TimeTailor Salon Booking Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedApr 15, 2026
PHP min version7.4
Downloads22

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

TimeTailor Salon Booking Developer Profile

timetailordev

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TimeTailor Salon Booking

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/timetailor-salon-booking/assets/css/tailwind.min.css/wp-content/plugins/timetailor-salon-booking/assets/css/style.css
Script Paths
/wp-content/plugins/timetailor-salon-booking/assets/js/features/public/setup-wizard/setup-wizard.js/wp-content/plugins/timetailor-salon-booking/assets/js/features/auth/choose-location/choose-location.js/wp-content/plugins/timetailor-salon-booking/assets/js/features/location/overview/overview.js/wp-content/plugins/timetailor-salon-booking/assets/js/features/location/embeds/embeds.js
Version Parameters
timetailor-salon-booking/assets/css/tailwind.min.css?ver=timetailor-salon-booking/assets/css/style.css?ver=timetailor-salon-booking/assets/js/features/public/setup-wizard/setup-wizard.js?ver=timetailor-salon-booking/assets/js/features/auth/choose-location/choose-location.js?ver=timetailor-salon-booking/assets/js/features/location/overview/overview.js?ver=timetailor-salon-booking/assets/js/features/location/embeds/embeds.js?ver=

HTML / DOM Fingerprints

JS Globals
window.ttsbs_ajax_urlwindow.ttsbs_noncewindow.ttsbs_api_basewindow.ttsbs_isAuthwindow.ttsbs_wizardSlugwindow.ttsbs_locale+1 more
FAQ

Frequently Asked Questions about TimeTailor Salon Booking