
Tourfic Toolkit Security & Risk Analysis
wordpress.org/plugins/travelfic-toolkitA companion plugin to the Travelfic and Ultimate Hotel Booking with which you can easily build your own Hotel, Accommodation, Tour & Travel Bookin …
Is Tourfic Toolkit Safe to Use in 2026?
Generally Safe
Score 98/100Tourfic Toolkit has a strong security track record. Known vulnerabilities have been patched promptly.
The travelfic-toolkit plugin v1.4.0 exhibits a mixed security posture. While it demonstrates good practices like 100% use of prepared statements for SQL queries and a high percentage of properly escaped output, significant concerns remain. The presence of 17 AJAX handlers, with 4 lacking authentication checks, presents a substantial attack surface that could be exploited by unauthenticated users. The static analysis also identified 7 instances of dangerous function usage, specifically `unserialize`, which can lead to remote code execution vulnerabilities if user-supplied data is not rigorously sanitized before being passed to this function. The vulnerability history, while currently showing no unpatched CVEs, reveals past issues including Missing Authorization and Cross-site Scripting (XSS). The fact that 2 medium severity vulnerabilities have occurred in the past, and the last one being relatively recent, suggests a pattern of potential oversight in secure coding practices that requires ongoing vigilance. Overall, the plugin has strengths in data handling for queries and output, but the unprotected entry points and the risky `unserialize` function, coupled with historical vulnerability patterns, indicate a moderate to high risk profile.
Key Concerns
- Unprotected AJAX handlers (4 out of 17)
- Dangerous function usage: unserialize (7 instances)
- Past medium severity vulnerabilities (2)
Tourfic Toolkit Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Travelfic Toolkit <= 1.3.3 - Missing Authorization
Travelfic Toolkit <= 1.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Tourfic Toolkit Code Analysis
Dangerous Functions Found
Bundled Libraries
Output Escaping
Data Flow Analysis
Tourfic Toolkit Attack Surface
AJAX Handlers 17
Shortcodes 1
WordPress Hooks 33
Maintenance & Trust
Tourfic Toolkit Maintenance & Trust
Maintenance Signals
Community Trust
Tourfic Toolkit Alternatives
WP Travel Engine – Tour Booking Plugin – Tour Operator Software
wp-travel-engine
WP Travel Engine is the most popular tour and travel booking WordPress plugin. Used by over 20,000 travel agency websites.
WP Travel Engine – Elementor Widgets | Create Travel Booking Website Using WordPress and Elementor
wte-elementor-widgets
WP Travel Engine – Elementor Widgets provides 20+ Elementor widgets to create travel and tour booking websites using WP Travel Engine and Elementor.
Travel Agency Companion – Create Tour & Travel Website Using WP Travel Engine
travel-agency-companion
It is a companion plugin for the Travel Agency theme to create travel and tour booking websites. Use it with WP Travel Engine to make the most of it.
Travel Booking Toolkit
travel-booking-toolkit
The Travel Booking Toolkit plugin works with the WP Travel Engine. It adds special widgets to the Travel Booking theme, making creating travel website …
WP Travel – Ultimate Travel Booking System, Tour Management Engine
wp-travel
WP Travel is the optimal choice among the WordPress Travel Booking Plugin and Tour Operator to Create Travel and Trekking Websites Without Coding!
Tourfic Toolkit Developer Profile
11 plugins · 97K total installs
How We Detect Tourfic Toolkit
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/travelfic-toolkit/assets/admin/lib/select2/select2.min.css/wp-content/plugins/travelfic-toolkit/assets/admin/css/style.css/wp-content/plugins/travelfic-toolkit/assets/app/css/style.min.css/wp-content/plugins/travelfic-toolkit/assets/admin/lib/select2/select2.min.js/wp-content/plugins/travelfic-toolkit/assets/admin/js/customizer.js/wp-content/plugins/travelfic-toolkit/assets/app/js/main.jstravelfic-toolkit/assets/admin/lib/select2/select2.min.css?ver=travelfic-toolkit/assets/admin/css/style.css?ver=travelfic-toolkit/assets/admin/js/customizer.js?ver=travelfic-toolkit/assets/app/js/main.js?ver=travelfic-toolkit/assets/app/css/style.min.css?ver=HTML / DOM Fingerprints
tf-notice-wrapper<!-- IMPORTANT: Include file from plugin if it is not available in theme --><!-- Loading Text Domain --><!-- Customizer Settings --><!-- Customizer Migrator -->+10 moredata-tf-notice-idtravelfic_toolkit_active_pluginstravelfic_toolkit_facts