
WP Auto Hotel Finder Security & Risk Analysis
wordpress.org/plugins/wp-auto-hotel-finderShow a detailed map of hotels with a shortcode or by cat/tag with auto searching for address inside post
Is WP Auto Hotel Finder Safe to Use in 2026?
Generally Safe
Score 85/100WP Auto Hotel Finder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-auto-hotel-finder v2.0 plugin exhibits a generally strong security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history are positive indicators. The code demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of properly escaped output. The limited attack surface, consisting of a single shortcode and no unprotected entry points, further contributes to its security. The plugin also avoids bundled libraries and external HTTP requests, which are common vectors for vulnerabilities.
However, there are notable areas for concern. The complete absence of nonce checks and capability checks, despite having entry points, is a significant weakness. This means that potentially any user, or even unauthenticated users, could trigger actions related to the shortcode without proper authorization or verification. While the current analysis shows no critical taint flows, this lack of checks drastically increases the potential for exploitation if vulnerabilities are introduced in the future or if certain functions within the shortcode are sensitive.
In conclusion, wp-auto-hotel-finder v2.0 has strengths in its SQL handling, output escaping, and limited attack surface, with no historical vulnerabilities. Nevertheless, the lack of nonce and capability checks represents a significant and inherent risk that needs to be addressed to prevent potential unauthorized actions and ensure robust security.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
WP Auto Hotel Finder Security Vulnerabilities
WP Auto Hotel Finder Code Analysis
Output Escaping
WP Auto Hotel Finder Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
WP Auto Hotel Finder Maintenance & Trust
Maintenance Signals
Community Trust
WP Auto Hotel Finder Alternatives
WP Google Maps Auto Business Place Finder
wp-google-maps-auto-business-place-finder
Show a detailed map of any kind of business places, like hotels, restaurants, airports, art galleries etc, with a shortcode or by cat/tag with auto se …
WP Auto Restaurant Finder
wp-auto-restaurant-finder
Show a detailed map of restaurants with a shortcode or by cat/tag with auto searching for address inside post
WP Google Auto Directions Path Finder
wp-google-auto-directions-path-finder
Calculates the best route between two points using google directions. With auto detection for both points.
WP Store Locator
wp-store-locator
An easy to use location management system that enables users to search for nearby physical stores.
WP Tripadvisor Review Widgets
review-widgets-for-tripadvisor
Embed Tripadvisor reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Tripadvisor reviews.
WP Auto Hotel Finder Developer Profile
6 plugins · 150 total installs
How We Detect WP Auto Hotel Finder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-auto-hotel-finder/css/stylemap.css/wp-content/plugins/wp-auto-hotel-finder/js/scriptmap.jswp-auto-hotel-finder/css/stylemap.css?ver=wp-auto-hotel-finder/js/scriptmap.js?ver=HTML / DOM Fingerprints
name="wphf_autocomplete_search"name="wphf_view_on_cat"name="wphf_view_on_tag"name="wphf_lat"name="wphf_default_title"name="wphf_lng"+16 more[wmhf{TITLE}{LAT}{LNG}