
WPCafe – Restaurant Menu, Online Food Ordering and Reservation Booking Solution Security & Risk Analysis
wordpress.org/plugins/wp-cafeComplete restaurant solution for restaurant menus, online food ordering, delivery, reservations and booking
Is WPCafe – Restaurant Menu, Online Food Ordering and Reservation Booking Solution Safe to Use in 2026?
Generally Safe
Score 91/100WPCafe – Restaurant Menu, Online Food Ordering and Reservation Booking Solution has a strong security track record. Known vulnerabilities have been patched promptly.
The wp-cafe plugin version 3.0.6 exhibits a mixed security posture. While the static analysis reveals good practices in many areas, such as a high percentage of prepared SQL statements and properly escaped output, there are notable concerns. The presence of two AJAX handlers without authentication checks presents a significant risk, potentially allowing unauthorized actions. The extensive vulnerability history, with 9 known CVEs including high-severity issues like PHP Remote File Inclusion and Cross-site Scripting, is a major red flag. The fact that the last vulnerability was very recent (2025-04-17) indicates a recurring pattern of security weaknesses, even though none are currently unpatched.
Despite the positive aspects of the code analysis regarding SQL and output escaping, the two unprotected AJAX endpoints are a direct and immediate risk. The historical vulnerability data suggests a fundamental challenge in the plugin's development lifecycle, with a history of severe vulnerabilities that require ongoing patching. This history, combined with the unprotected entry points, suggests a plugin that may be prone to exploitation if not meticulously maintained and updated. The absence of critical taint flow issues and the low number of file operations or external HTTP requests are positive, but they do not outweigh the direct security gaps identified.
Key Concerns
- Unprotected AJAX handlers
- High number of past high/medium severity CVEs
- Recent vulnerability discovered
WPCafe – Restaurant Menu, Online Food Ordering and Reservation Booking Solution Security Vulnerabilities
CVEs by Year
Severity Breakdown
9 total CVEs
WPCafe <= 2.2.32 - Authenticated (Contributor+) Local File Inclusion
WPCafe <= 2.2.31 - Authenticated (Contributor+) Local File Inclusion
WPCafe <= 2.2.28 - Authenticated (Contributor+) Local File Inclusion
WPCafe <= 2.2.27 - Authenticated (Contributor+) Local File Inclusion
WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.25 - Authenticated (Contributor+) File inclusion via Shortcode
WPCafe – Online Food Ordering, Restaurant Menu, Delivery, and Reservations for WooCommerce <= 2.2.24 - Authenticated (Contributor+) Stored Cross-Site Scripting via Reservation Form Shortcode
WPCafe <= 2.2.23 - Unauthenticated Blind Server-Side Request Forgery
WPCafe <= 2.2.22 - Missing Authorization
WPCafe – Food Menu, WooCommerce Food Ordering, Food Delivery, Pickup and Restaurant Reservation <= 2.1.4 - Cross-Site Scripting
WPCafe – Restaurant Menu, Online Food Ordering and Reservation Booking Solution Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WPCafe – Restaurant Menu, Online Food Ordering and Reservation Booking Solution Attack Surface
AJAX Handlers 15
WordPress Hooks 102
Maintenance & Trust
WPCafe – Restaurant Menu, Online Food Ordering and Reservation Booking Solution Maintenance & Trust
Maintenance Signals
Community Trust
WPCafe – Restaurant Menu, Online Food Ordering and Reservation Booking Solution Alternatives
Orderable – WordPress Restaurant Online Ordering System and Food Ordering Plugin
orderable
Take your restaurant/food business online with the online ordering system plugin for WordPress, Orderable.
Food Menu – Restaurant Menu & Online Ordering for WooCommerce
tlp-food-menu
A Simple Food & Restaurant Menu Display Plugin for Restaurant, Cafes, Fast Food, Coffee House with WooCommerce Online Ordering.
Restaurant Menu and Food Ordering
mp-restaurant-menu
Create and maintain modern online menus for almost any kind of restaurant. Sell food and beverages online. All in one plugin.
Single Page Restaurant Menu for WooCommerce
single-page-restaurant-menu-for-woocommerce
This plugin is developed to list all woocommerce products/menus in a single page with category and editable cart information.
BookMyOrder – Food ordering, delivery, takeaway and reservation for restaurants
food-ordering-for-restaurants
BookMyOrder WordPress Plugin
WPCafe – Restaurant Menu, Online Food Ordering and Reservation Booking Solution Developer Profile
8 plugins · 20K total installs
How We Detect WPCafe – Restaurant Menu, Online Food Ordering and Reservation Booking Solution
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-cafe/assets/css/blocks.style.build.css/wp-content/plugins/wp-cafe/assets/css/frontend.css/wp-content/plugins/wp-cafe/assets/css/frontend.style.build.css/wp-content/plugins/wp-cafe/assets/css/admin.css/wp-content/plugins/wp-cafe/assets/js/frontend.asset.php/wp-content/plugins/wp-cafe/assets/js/blocks.editor.build.js/wp-content/plugins/wp-cafe/assets/js/frontend.js/wp-content/plugins/wp-cafe/assets/js/admin.js/wp-content/plugins/wp-cafe/assets/js/blocks.editor.build.js/wp-content/plugins/wp-cafe/assets/js/frontend.js/wp-content/plugins/wp-cafe/assets/js/admin.jswp-cafe/assets/css/blocks.style.build.css?ver=wp-cafe/assets/css/frontend.css?ver=wp-cafe/assets/css/frontend.style.build.css?ver=wp-cafe/assets/css/admin.css?ver=wp-cafe/assets/js/blocks.editor.build.js?ver=wp-cafe/assets/js/frontend.js?ver=wp-cafe/assets/js/admin.js?ver=HTML / DOM Fingerprints
wpcafe-migration-noticewpcafe-run-migrationwpcafe-migration-messagedata-notice="migration"data-rest-urldata-noncedata-success-messagedata-error-message/wpcafe/v2/migration/run