
YOGO Booking Security & Risk Analysis
wordpress.org/plugins/yogo-bookingThe easiest way to embed YOGO Booking on your Wordpress website.
Is YOGO Booking Safe to Use in 2026?
Generally Safe
Score 99/100YOGO Booking has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of yogo-booking v1.6.6 reveals a generally strong security posture. The plugin exhibits excellent practices by using prepared statements for all SQL queries and ensuring all output is properly escaped. Furthermore, the absence of dangerous functions, file operations, and external HTTP requests are positive indicators. The limited attack surface is also a good sign. However, the complete absence of nonce checks and the presence of only one capability check across all entry points are significant concerns. This lack of robust authorization mechanisms means that if an attacker can find a way to trigger these entry points, they might be able to perform actions without proper verification.
The vulnerability history indicates a single past medium-severity vulnerability, specifically Cross-site Scripting (XSS). While this vulnerability is reported as patched, the presence of such a vulnerability in the past, coupled with the current lack of nonce checks, suggests a potential for similar issues if input handling is not meticulously reviewed. The fact that the last vulnerability was in the future (2025-01-06) is also highly unusual and likely an error in the provided data. Despite the good practices in SQL and output handling, the oversight in authorization and nonce checks represents a notable weakness that could be exploited.
Key Concerns
- No nonce checks on entry points
- Only one capability check across 10 entry points
- Past medium severity CVE (XSS)
YOGO Booking Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
YOGO Booking <= 1.6.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
YOGO Booking Code Analysis
Output Escaping
YOGO Booking Attack Surface
Shortcodes 10
WordPress Hooks 5
Maintenance & Trust
YOGO Booking Maintenance & Trust
Maintenance Signals
Community Trust
YOGO Booking Alternatives
Yoga Schedule Momoyoga
momoyoga-integration
Show your Momoyoga class schedule on your WordPress website.
Gym Builder – Fitness, Gym, Class Schedule Maker Plugin
gym-builder
GymBuilder simplifies gym management with class schedules,trainer profiles,fitness calculators,member management,and shortcode generators.
Appointment Hour Booking – Booking Calendar
appointment-hour-booking
Appointment Hour Booking is a plugin for creating booking forms for appointments with a start time and a defined duration within a schedule.
MotoPress Appointment Booking
motopress-appointment-lite
MotoPress Appointment Booking makes it easy for time and service-based businesses to accept bookings and appointments online.
Event Tickets Manager for WooCommerce
event-tickets-manager-for-woocommerce
Use this powerful WordPress event plugin to create and sell events, manage tickets, check-ins, recurring schedules, venues, and attendee details with …
YOGO Booking Developer Profile
1 plugin · 200 total installs
How We Detect YOGO Booking
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yogo-booking/build/yogo-booking.css/wp-content/plugins/yogo-booking/build/yogo-booking.jsHTML / DOM Fingerprints
yogo-calendaryogo-teachersyogo-eventsyogo-pricesyogo-productsyogo-event-buttonyogo-class-pass-buttonyogo-membership-button+1 moredata-branchdata-class-typedata-teacherdata-start-datedata-teachersdata-event-group+9 moreYOGO_APP_SERVERyogoWidgetSettings<div class="yogo-calendar"<div class="yogo-teachers"<div class="yogo-events"<div class="yogo-prices"