Yala Travel Companion Security & Risk Analysis

wordpress.org/plugins/yala-travel-companion

Used for Yala Travel Theme for Itinerary And Extra fields.

10 active installs v1.0.1 PHP + WP 4.7+ Updated Jun 12, 2020
themes
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Yala Travel Companion Safe to Use in 2026?

Generally Safe

Score 85/100

Yala Travel Companion has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

Based on the static analysis, yala-travel-companion v1.0.1 exhibits a strong security posture. The plugin has no identified attack surface points, such as AJAX handlers, REST API routes, or shortcodes. Furthermore, all SQL queries are properly prepared, and all output is correctly escaped, indicating good development practices in preventing common web vulnerabilities.

The absence of dangerous functions, file operations, and external HTTP requests, coupled with the presence of nonce and capability checks for all identified functions, further reinforces its secure design. The taint analysis also shows no concerning flows, indicating that user-supplied data is not being handled in an unsafe manner. The plugin also has a clean vulnerability history, with no recorded CVEs, suggesting a history of secure development and maintenance.

While the plugin demonstrates excellent adherence to secure coding principles, the complete lack of any identified entry points (AJAX, REST, shortcodes, cron) in the static analysis, combined with the fact that all 4 nonces and capability checks are present, raises a slight suspicion. It's possible that the analysis might be incomplete or that the plugin is extremely basic, offering minimal functionality. However, based solely on the provided data, the plugin appears to be highly secure and low-risk.

Vulnerabilities
None known

Yala Travel Companion Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Yala Travel Companion Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
27 escaped
Nonce Checks
4
Capability Checks
4
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped27 total outputs
Attack Surface

Yala Travel Companion Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionsave_postmetabox\include-excludes.php:57
actionadmin_initmetabox\include-excludes.php:59
actionsave_postmetabox\map-routes.php:56
actionadmin_initmetabox\map-routes.php:58
actionadmin_initmetabox\meta-boxes.php:7
actionsave_postmetabox\meta-boxes.php:108
actionadd_meta_boxesmetabox\travel-metaboxes.php:16
actionsave_postmetabox\travel-metaboxes.php:209
actionsave_postmetabox\travel-metaboxes.php:240
actionwp_restore_post_revisionmetabox\travel-metaboxes.php:265
filter_wp_post_revision_fieldsmetabox\travel-metaboxes.php:280
filter_wp_post_revision_field_my_metametabox\travel-metaboxes.php:290
Maintenance & Trust

Yala Travel Companion Maintenance & Trust

Maintenance Signals

WordPress version tested5.4.19
Last updatedJun 12, 2020
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Yala Travel Companion Developer Profile

YalaThemes

2 plugins · 70 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Yala Travel Companion

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yala-travel-companion/metabox/map-routes.php/wp-content/plugins/yala-travel-companion/metabox/include-excludes.php/wp-content/plugins/yala-travel-companion/metabox/meta-boxes.php/wp-content/plugins/yala-travel-companion/inc/Activate.php/wp-content/plugins/yala-travel-companion/inc/Deactivate.php
Version Parameters
yala-travel-companion/style.css?ver=yala-travel-companion/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
w20repeater-sectionitem
HTML Comments
<!--This program is free software; you can redistribute it and/or modify it under the terms of the GNU General Public License as published by the Free Software Foundation; either version 2 of the License, or (at your option) any later version.--><!--This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU General Public License for more details.--><!--You should have received a copy of the GNU General Public License along with this program; if not, write to the Free Software Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301, USA.--><!--If this file is ccalled directly, abort!!!-->+7 more
Data Attributes
ytc_include_excludeytc_map_routeytc_itinerary_repeatable_fieldsytc_repeatable_meta_box_nonce
JS Globals
ytc_allowed_html
FAQ

Frequently Asked Questions about Yala Travel Companion