ZOOZA Security & Risk Analysis

wordpress.org/plugins/zooza

This plugin enables integration of Zooza widgets to your website. An existing Zooza account is required for this plugin to work.

50 active installs v1.1.7 PHP + WP 3.0.1+ Updated Unknown
bookingchildreneducationfranchisekids-activities
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ZOOZA Safe to Use in 2026?

Generally Safe

Score 100/100

ZOOZA has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "zooza" plugin v1.1.7 exhibits a generally strong security posture based on the provided static analysis. The complete absence of dangerous functions, raw SQL queries, file operations, and the use of prepared statements for all SQL queries are significant strengths. The plugin also correctly handles the majority of its output escaping, indicating good development practices to prevent cross-site scripting vulnerabilities. Furthermore, the lack of any recorded vulnerabilities or CVEs in its history is a very positive indicator of its past security reliability.

However, there are areas for concern that prevent a perfect score. The absence of nonce checks and capability checks on all entry points, particularly the single shortcode present, creates a potential blind spot. If the shortcode were to interact with sensitive data or functionality, this lack of authentication and authorization checks could lead to vulnerabilities. Additionally, while only one external HTTP request is made, its context and sanitization are not detailed, and a relatively high percentage of outputs (26%) are not properly escaped, which could still pose a risk of XSS if those outputs are user-controlled.

In conclusion, "zooza" v1.1.7 is a plugin with a good foundation in secure coding practices, particularly concerning SQL injection and dangerous functions. Its clean vulnerability history is reassuring. Nevertheless, the identified gaps in authentication/authorization for its entry points and the unescaped output are notable weaknesses that require attention to ensure a robust security profile.

Key Concerns

  • Missing capability checks on entry points
  • Missing nonce checks on entry points
  • Unescaped output detected (26%)
Vulnerabilities
None known

ZOOZA Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

ZOOZA Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
26 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

74% escaped35 total outputs
Attack Surface

ZOOZA Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[zooza] public\class-zooza-public.php:190
WordPress Hooks 9
actioninitincludes\class-zooza.php:142
actionadmin_enqueue_scriptsincludes\class-zooza.php:157
actionadmin_enqueue_scriptsincludes\class-zooza.php:158
actionadmin_menuincludes\class-zooza.php:159
actionadmin_initincludes\class-zooza.php:160
actionwp_enqueue_scriptsincludes\class-zooza.php:175
actionwp_enqueue_scriptsincludes\class-zooza.php:176
actionthe_contentincludes\class-zooza.php:177
actioninitpublic\class-zooza-public.php:56
Maintenance & Trust

ZOOZA Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

ZOOZA Developer Profile

Martin@Zooza

1 plugin · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ZOOZA

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/zooza/assets/css/zooza.css/wp-content/plugins/zooza/assets/js/zooza-admin.js/wp-content/plugins/zooza/assets/js/zooza.js/wp-content/plugins/zooza/assets/css/bootstrap.min.css/wp-content/plugins/zooza/assets/css/owl.carousel.min.css
Script Paths
/wp-content/plugins/zooza/assets/js/zooza.js/wp-content/plugins/zooza/assets/js/zooza-admin.js
Version Parameters
zooza/assets/css/zooza.css?ver=zooza/assets/js/zooza-admin.js?ver=zooza/assets/js/zooza.js?ver=zooza/assets/css/bootstrap.min.css?ver=zooza/assets/css/owl.carousel.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
zooza-form-wrapperzooza-calendar-widgetzooza-widget-loginzooza-widget-registrationzooza-user-avatarzooza-account-balance
Data Attributes
data-zooza-iddata-zooza-shortcode-typedata-zooza-api-url
JS Globals
zoozaApiUrlzoozaApiKeyzoozaClientSecretzoozaId
Shortcode Output
[zooza_registration][zooza_login][zooza_calendar][zooza_profile]
FAQ

Frequently Asked Questions about ZOOZA