TP Travel Package Security & Risk Analysis

wordpress.org/plugins/tp-travel-package

Enhance your travel sites more efficiently. Allow user to utilize post types and meta data on your site with TP Travel Package.

10 active installs v1.0.4 PHP + WP 4.7+ Updated Aug 15, 2022
custom-post-typemeta-datatravel
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TP Travel Package Safe to Use in 2026?

Generally Safe

Score 85/100

TP Travel Package has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The static analysis of the 'tp-travel-package' v1.0.4 plugin indicates a strong security posture based on the provided code signals. The absence of dangerous functions, the exclusive use of prepared statements for SQL queries, and 100% proper output escaping are all positive indicators. Furthermore, the presence of nonce and capability checks, along with no file operations or external HTTP requests, suggests good defensive coding practices were followed. The zero reported CVEs and no recorded vulnerability history further bolster this assessment, implying a well-maintained and secure plugin to date.

However, the most significant observation is the complete lack of identified entry points (AJAX handlers, REST API routes, shortcodes, cron events). While this might suggest a very simple or integrated plugin, it also means the static analysis had no interactive elements to deeply examine for taint flows or unsanitized paths. Without these entry points, the taint analysis could not be fully performed, leaving a blind spot. Therefore, while the current code appears robust, the limited attack surface analysis and absence of taint flow data mean a comprehensive risk assessment is challenging.

In conclusion, 'tp-travel-package' v1.0.4 exhibits excellent code hygiene for the parts that were analyzed. Its adherence to secure coding standards for SQL, output, and authentication checks is commendable. The lack of historical vulnerabilities is also a strong positive. The primary concern is the lack of observable entry points for deeper taint analysis, which prevents a definitive declaration of zero risk in all potential execution paths. The current assessment leans towards low risk, but with a caveat regarding the incomplete attack surface visibility.

Vulnerabilities
None known

TP Travel Package Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

TP Travel Package Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
43 escaped
Nonce Checks
2
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped43 total outputs
Attack Surface

TP Travel Package Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
filterthe_contentincludes\tp-travel-package-functions.php:247
actionadd_meta_boxestp-metabox\class-tp-destination-metabox.php:20
actionsave_posttp-metabox\class-tp-destination-metabox.php:21
actionadd_meta_boxestp-metabox\class-tp-package-metabox.php:20
actionsave_posttp-metabox\class-tp-package-metabox.php:21
actioninittp-post-type\class-tp-destination.php:20
actioninittp-post-type\class-tp-package.php:20
filtertemplate_includetp-travel-package.php:57
filtertemplate_includetp-travel-package.php:60
actionwp_enqueue_scriptstp-travel-package.php:63
actionadmin_enqueue_scriptstp-travel-package.php:66
actionadmin_inittp-travel-package.php:69
actionadmin_noticestp-travel-package.php:170
Maintenance & Trust

TP Travel Package Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedAug 15, 2022
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

TP Travel Package Developer Profile

themepalace

148 plugins · 15K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
265 days
View full developer profile
Detection Fingerprints

How We Detect TP Travel Package

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tp-travel-package/assets/css/admin-style.min.css/wp-content/plugins/tp-travel-package/assets/css/jquery-ui.min.css/wp-content/plugins/tp-travel-package/assets/js/admin-custom.min.js/wp-content/plugins/tp-travel-package/assets/css/style.min.css
Version Parameters
tp-travel-package/assets/css/admin-style.min.css?ver=tp-travel-package/assets/css/jquery-ui.min.css?ver=tp-travel-package/assets/js/admin-custom.min.js?ver=tp-travel-package/assets/css/style.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
tp-destination-titletp-package-titletp-destination-contenttp-package-content
HTML Comments
<!-- TP Travel Package Plugin Options --><!-- TP Travel Package Destination Options --><!-- TP Travel Package Package Options --><!-- TP Travel Package Single Destination Options -->+1 more
Data Attributes
data-destination-iddata-package-iddata-tp-destination-quotedata-tp-package-price
JS Globals
TP_Travel_Package_AdminTP_Travel_Package_Frontend
Shortcode Output
[tp_travel_package_destinations][tp_travel_package_packages][tp_travel_package_destination_details][tp_travel_package_package_details]
FAQ

Frequently Asked Questions about TP Travel Package