
Tripadvisor Shortcode Security & Risk Analysis
wordpress.org/plugins/tripadvisor-shortcodeI have been told by TripAdvisor that they are about to turn off the business owner rss feeds. This plugin no longer works.
Is Tripadvisor Shortcode Safe to Use in 2026?
Use With Caution
Score 63/100Tripadvisor Shortcode has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'tripadvisor-shortcode' plugin version 2.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and having a limited attack surface with only one entry point (a shortcode) and no unprotected AJAX handlers or REST API routes. The presence of a capability check on its single shortcode is also a positive indicator for access control.
However, significant concerns arise from the lack of output escaping. With 100% of its three identified outputs being unescaped, this presents a clear vulnerability to Cross-Site Scripting (XSS) attacks. This is further validated by its vulnerability history, which includes a medium severity XSS vulnerability, indicating a recurring pattern of insecure output handling. The absence of nonce checks is also a point of concern, as it could potentially be exploited in conjunction with other weaknesses, although the current data does not highlight specific flows that would leverage this.
In conclusion, while the plugin avoids common pitfalls like raw SQL queries and a broad attack surface, the pervasive issue of unescaped output creates a significant security risk. The past XSS vulnerability strongly suggests this is not an isolated incident, and the unpatched status of a medium severity vulnerability dated in the future is a critical alarm bell. Users should exercise extreme caution and ensure the plugin is updated to a version that addresses these output escaping and vulnerability issues.
Key Concerns
- Unpatched medium severity CVE
- 100% of outputs unescaped
- Missing nonce checks
Tripadvisor Shortcode Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Tripadvisor Shortcode <= 2.2 - Authenticated (Administrator+) Stored Cross-Site Scripting
Tripadvisor Shortcode Release Timeline
Tripadvisor Shortcode Code Analysis
Output Escaping
Tripadvisor Shortcode Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
Tripadvisor Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
Tripadvisor Shortcode Alternatives
WP Tripadvisor Review Widgets
review-widgets-for-tripadvisor
Embed Tripadvisor reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Tripadvisor reviews.
Reviews Widgets for Google, Yelp & TripAdvisor
fb-reviews-widget
Combine Facebook recommendations with Google, Yelp and TripAdvisor reviews in a widget, block or shortcode. Build a trusted website!
WP TripAdvisor Review Slider
wp-tripadvisor-review-slider
Create a TripAdvisor review slider! Now with User Images! Easily display your TripAdvisor reviews in your Posts, Pages, and Widget areas!
Booking.com Official Search Box
bookingcom-official-searchbox
The official Booking.com search box is a user-friendly, customisable plugin to add the Booking.com search box to your own website in two easy steps.
Agoda Affiliate Partners Text Link Generator
agoda-affiliate-partners-text-link-generator
This tool was built so that our affiliate partners can easily generate text links in Wordpress.
Tripadvisor Shortcode Developer Profile
5 plugins · 9K total installs
How We Detect Tripadvisor Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
http://www.tripadvisor.com/FeedsJS?f=hotels&defaultStyles=n&d=http://c1.tacdn.com/img/logos_ta/logo_125px.gifhttp://c1.tacdn.com/img/flags/uk.gifhttp://c1.tacdn.com/img/flags/es.gifhttp://c1.tacdn.com/img/flags/de.gifhttp://c1.tacdn.com/img/flags/fr.gif+1 moreHTML / DOM Fingerprints
wrapdonate_containerTA_HeaderTA_LinkTA_ContainerTA_Flags2This plugin no longer works. TripAdvisor are about to turn off the business rss feeds that this plugin need.name="tripadvisor_url"name="tripadvisor_name"name="tripadvisor_id"name="tripadvisor_buff"window.realAlertwindow.alert<script src="http://www.tripadvisor.com/FeedsJS?f=hotels&defaultStyles=n&d=<script>window.realAlert = window.alert;window.alert = function() {};<div id="TA_Header">brought to you by<br/>