
ZOOZA Security & Risk Analysis
wordpress.org/plugins/zoozaThis plugin enables integration of Zooza widgets to your website. An existing Zooza account is required for this plugin to work.
Is ZOOZA Safe to Use in 2026?
Generally Safe
Score 100/100ZOOZA has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "zooza" plugin v1.1.7 exhibits a generally strong security posture based on the provided static analysis. The complete absence of dangerous functions, raw SQL queries, file operations, and the use of prepared statements for all SQL queries are significant strengths. The plugin also correctly handles the majority of its output escaping, indicating good development practices to prevent cross-site scripting vulnerabilities. Furthermore, the lack of any recorded vulnerabilities or CVEs in its history is a very positive indicator of its past security reliability.
However, there are areas for concern that prevent a perfect score. The absence of nonce checks and capability checks on all entry points, particularly the single shortcode present, creates a potential blind spot. If the shortcode were to interact with sensitive data or functionality, this lack of authentication and authorization checks could lead to vulnerabilities. Additionally, while only one external HTTP request is made, its context and sanitization are not detailed, and a relatively high percentage of outputs (26%) are not properly escaped, which could still pose a risk of XSS if those outputs are user-controlled.
In conclusion, "zooza" v1.1.7 is a plugin with a good foundation in secure coding practices, particularly concerning SQL injection and dangerous functions. Its clean vulnerability history is reassuring. Nevertheless, the identified gaps in authentication/authorization for its entry points and the unescaped output are notable weaknesses that require attention to ensure a robust security profile.
Key Concerns
- Missing capability checks on entry points
- Missing nonce checks on entry points
- Unescaped output detected (26%)
ZOOZA Security Vulnerabilities
ZOOZA Code Analysis
Output Escaping
ZOOZA Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
ZOOZA Maintenance & Trust
Maintenance Signals
Community Trust
ZOOZA Alternatives
LatePoint – Calendar Booking Plugin for Appointments and Events
latepoint
Optimize your appointment scheduling with our plugin. Sync calendars, automate reminders, and keep your bookings organized.
Tutor LMS – eLearning and online course solution
tutor
A complete WordPress LMS plugin to create any eLearning website easily.
Booking for Appointments and Events Calendar – Amelia
ameliabooking
Amelia is a powerful booking plugin for appointments and events. Manage scheduling, calendars, and availability with an all-in-one booking system.
LearnPress – WordPress LMS Plugin for Create and Sell Online Courses
learnpress
A WordPress LMS Plugin to create WordPress Learning Management System. Turn your WordPress to LMS WordPress Website with Courses, Lessons, Quizzes &am …
Online Scheduling and Appointment Booking System – Bookly
bookly-responsive-appointment-booking-tool
Appointment booking system for WordPress — schedule appointments, manage calendars, send reminders, take payments. Start booking today!
ZOOZA Developer Profile
1 plugin · 50 total installs
How We Detect ZOOZA
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zooza/assets/css/zooza.css/wp-content/plugins/zooza/assets/js/zooza-admin.js/wp-content/plugins/zooza/assets/js/zooza.js/wp-content/plugins/zooza/assets/css/bootstrap.min.css/wp-content/plugins/zooza/assets/css/owl.carousel.min.css/wp-content/plugins/zooza/assets/js/zooza.js/wp-content/plugins/zooza/assets/js/zooza-admin.jszooza/assets/css/zooza.css?ver=zooza/assets/js/zooza-admin.js?ver=zooza/assets/js/zooza.js?ver=zooza/assets/css/bootstrap.min.css?ver=zooza/assets/css/owl.carousel.min.css?ver=HTML / DOM Fingerprints
zooza-form-wrapperzooza-calendar-widgetzooza-widget-loginzooza-widget-registrationzooza-user-avatarzooza-account-balancedata-zooza-iddata-zooza-shortcode-typedata-zooza-api-urlzoozaApiUrlzoozaApiKeyzoozaClientSecretzoozaId[zooza_registration][zooza_login][zooza_calendar][zooza_profile]