
Travelmanager Buchungssoftware Security & Risk Analysis
wordpress.org/plugins/travelmanager-buchungssoftwareDies ist die README-Datei für das Travelmanager WordPress Plugin. Für Informationen in Englisch, sehen Sie bitte die englische Version der README.
Is Travelmanager Buchungssoftware Safe to Use in 2026?
Generally Safe
Score 100/100Travelmanager Buchungssoftware has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "travelmanager-buchungssoftware" v22.27 exhibits a concerning security posture, primarily due to a large number of unprotected AJAX handlers. While the absence of known CVEs and the use of prepared statements for SQL queries are positive indicators, the significant attack surface exposed without proper authentication checks presents a substantial risk. The static analysis revealed 18 AJAX handlers lacking authentication, and the taint analysis identified 5 flows with unsanitized paths, indicating a potential for unauthorized data manipulation or execution. The complete lack of nonce checks and capability checks on these entry points exacerbates the risk, making it easier for attackers to trigger malicious actions. The low percentage of properly escaped output further suggests a vulnerability to cross-site scripting (XSS) attacks. Despite the lack of historical vulnerabilities, the current codebase contains critical weaknesses that need immediate attention.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized paths in taint flows
- Missing nonce checks
- Missing capability checks
- Low output escaping coverage
Travelmanager Buchungssoftware Security Vulnerabilities
Travelmanager Buchungssoftware Code Analysis
Output Escaping
Data Flow Analysis
Travelmanager Buchungssoftware Attack Surface
AJAX Handlers 18
Shortcodes 3
WordPress Hooks 8
Maintenance & Trust
Travelmanager Buchungssoftware Maintenance & Trust
Maintenance Signals
Community Trust
Travelmanager Buchungssoftware Alternatives
No alternatives data available yet.
Travelmanager Buchungssoftware Developer Profile
2 plugins · 2K total installs
How We Detect Travelmanager Buchungssoftware
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/travelmanager-buchungssoftware/libs/public-enqueue.js/wp-content/plugins/travelmanager-buchungssoftware/libs/public-enqueue.csstravelmanager-buchungssoftware/libs/public-enqueue.js?ver=travelmanager-buchungssoftware/libs/public-enqueue.css?ver=HTML / DOM Fingerprints
tm-booking-widgettravelmanager_teasertm-event-booking-formtm_widget<!-- START Travelmanager Booking Widget --><!-- END Travelmanager Booking Widget --><!-- Travelmanager Content Wrapper --><!-- END Travelmanager Content Wrapper -->+6 moredata-accountdata-calldata-linien_iddata-linien_idsdata-startdata-stop+19 morewindow.tm_dialogvar dialoge_data<div class='tm-booking-widget'<div class='travelmanager_teaser'<div class='tm-event-booking-form'<div class='tm_widget'