
WP Taxi Me Security & Risk Analysis
wordpress.org/plugins/wp-taxi-meGet customers to your business by allowing them to order a taxi to your site via Uber
Is WP Taxi Me Safe to Use in 2026?
Generally Safe
Score 85/100WP Taxi Me has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-taxi-me" v2.6.1 plugin exhibits a generally good security posture based on the provided static analysis. The absence of known CVEs and a clean vulnerability history are significant strengths, suggesting a well-maintained and secure codebase. The plugin also demonstrates good practices regarding SQL queries, exclusively using prepared statements, which mitigates SQL injection risks. Furthermore, the attack surface is minimal, with only one shortcode and no unprotected entry points identified.
However, there are areas for concern. The low percentage of properly escaped output (9%) is a notable weakness, indicating a potential risk of Cross-Site Scripting (XSS) vulnerabilities. With 23 total outputs and only 2 properly escaped, a significant number could be susceptible to malicious input. The complete lack of nonce checks and capability checks is also concerning, as these are fundamental security mechanisms for WordPress plugins. While the current attack surface is small, the absence of these checks means that even a single entry point could be exploited if it receives unsanitized user input.
In conclusion, while "wp-taxi-me" v2.6.1 benefits from a strong vulnerability history and good SQL practices, the insufficient output escaping and missing authorization checks represent significant security weaknesses. The plugin needs to address its output sanitization and implement proper nonce and capability checks to improve its overall security. The current score reflects these critical areas for improvement.
Key Concerns
- Insufficient output escaping
- Missing nonce checks
- Missing capability checks
WP Taxi Me Security Vulnerabilities
WP Taxi Me Code Analysis
Output Escaping
WP Taxi Me Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
WP Taxi Me Maintenance & Trust
Maintenance Signals
Community Trust
WP Taxi Me Alternatives
Widgets for Google Reviews
wp-reviews-plugin-for-google
Embed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
Click to Chat – HoliThemes
click-to-chat-for-whatsapp
WhatsApp Chat🔥. Let's make your Web page visitors contact you through 'WhatsApp', 'WhatsApp Business'. Add matching Widget✅
Social Chat – Click To Chat App Button
wp-whatsapp-chat
WhatsApp Chat🔥 allows you to enhance customer engagement! Integrate "WhatsApp" or "WhatsApp Business" with a single click.
Reviews Feed – Add Testimonials and Customer Reviews From Google Reviews, Yelp, TripAdvisor, and More
reviews-feed
No API key required. Display Yelp and Google reviews for any business in a clean, customizable feed on your site.
WP Chat App
wp-whatsapp
Integrate WhatsApp experience directly into your WordPress website.
WP Taxi Me Developer Profile
13 plugins · 7K total installs
How We Detect WP Taxi Me
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-taxi-me/languages/wp-taxi-me/css/taximebutton.css?ver=HTML / DOM Fingerprints
taxibuttonwrappertaximebuttonRAW API RETURN, SWITCH DEBUG OFF TO HIDE THIS: data-client_id<p class="taxibuttonwrapper"><a href="uber://?action=setPickup&pickup=my_location&dropoff[nickname]=<p class="taxibuttonwrapper"><a href="https://m.uber.com/sign-up?client_id=<p class="taxibuttonwrapper"><a href="WP Taxi Me</a> by <a href="https://winwar.co.uk/">Winwar Media</a></p>