Plugin Pulse
← Pulse

WP Hotel Booking

by ThimPress · Booking & Events

Also makes 19 other plugins · 185.1K+ installs across the portfolio →

WordPress Hotel Booking Plugin - A complete hotel booking reservation plugin for WordPress.

How scoring works →
81 Health · B
Maintenance 100/100
Rating quality 67/100
Support 70/100

81 health vs 67 average across 979 Booking & Events plugins

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

80 / 100

Well optimized

Biggest win: Support resolution

Update recency 100/100
WP compatibility 100/100
Rating quality 77/100
Listing tuning 100/100
Support resolution 0/100

To rank higher: Mark more forum threads resolved — the resolved ratio feeds the ranking.

Get the full rank-higher report →

Daily downloads

Since 2022-10-05 · 1,421 days · wp.org + Plugin Pulse archive

-56% vs prior 30d
81Downloads · Aug 26

30-day downloads

Rolling 30-day volume · peaks are release surges

3.0K

now · peak 13.3K

3K30d downloads · Aug 26

Directory rank vs rivals

wp.org popularity rank over time · higher is better · when a rival's line climbs above yours, they've overtaken you

WP Hotel Booking · #2597 you Hotel Booking for Wo · #15981 MotoPress Hotel Book · #1961 MotoPress Hotel Book · #2136

Rating trend

Star average over time · dips mark rough releases

3.7Stars · Aug 26

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

429per 1k installs · Aug 26

Release cadence

Actively maintained
from wp.org release tags

How often this plugin actually ships. A steady rhythm is the maintenance signal a single "last updated" date can't show.

11

releases in the last 12 months

1mo ago

latest release · v2.3.3

47

tagged releases on record

Recent releases

2.3.3 · 1mo ago2.3.2 · 2mo ago2.3.1 · 3mo ago2.3.0 · 6mo ago2.2.9 · 7mo ago2.2.8 · 8mo ago2.2.7 · 9mo ago2.2.6 · 9mo ago2.2.5 · 9mo ago2.2.4 · 10mo ago2.2.3 · 12mo ago2.2.2 · 1.0y ago2.2.1 · 1.1y ago2.2.0 · 1.3y ago

What its installed base runs

via wordpress.org

Share of active installs on each version of this plugin · 41% run the current release. Green is the current release; a big slice on older versions is a user base that has stopped updating.

v2.3 41%
v2.2 18%
v1.10 13%
v2.0 9.8%
v2.1 9.5%
v1.9 7.4%
v1.6 1%

Estimated active installs

The public count shows “7K+”. Our estimate pins where the real number sits.

tracked estimate
7K–8K ≈7.6K

Refined from the date this plugin crossed into its current band.

Install history · since 2017-05-01 · 1,429 observations

7KInstalls · Aug 26

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from. A declining trend compresses what a buyer would pay.

Details

Version
2.3.4
Last updated
3d ago
Added
2016-02-28 · 10 yrs old
Requires WP
6.4
Tested up to
7.1
Requires PHP
7.4

Recent reviews

All reviews on wp.org ↗
  1. jmacwell
    3mo ago

    Great program and the support was timely and effective. Love it.

    Read on wp.org ↗
  2. Dunos
    7mo ago

    Great hotel booking plugin with solid features. I love this team and hope they keep updating it in the future.

    Read on wp.org ↗
  3. MhrTheme
    1.3y ago

    I got the best support from the plugin team.

    Read on wp.org ↗
  4. niki1973
    1.6y ago

    Minimum night reservation in settings it doesn’t work

    Read on wp.org ↗
  5. balken
    1.9y ago

    You need loads of plugins to make this one “work” – booking is a mess, useless design on that too DONT DO IT

    Read on wp.org ↗
  6. vinciego
    2.2y ago

    I use official template from WordPress… And the plugin is not even compatible with that

    Read on wp.org ↗
  7. martegraphics
    2.5y ago

    I don’t recommend. it worked for a few days then only bugs

    Read on wp.org ↗
  8. jarvindesign
    2.6y ago

    The plugin is full of bugs This topic was modified 2 years, 5 months ago by jarvindesign.

    Read on wp.org ↗

Latest updates

via wp.org changelog

Recent releases and news for this plugin

  1. 2026-07-20 Version 2.3.4 ~ Fixed: security from Levi report. 2.3.4
  2. 2026-07-16 Version 2.3.3 ~ Fixed: security. 2.3.3
  3. 2026-06-23 Version 2.3.2 ~ Fixed: security. ~ Fixed: minor bugs. 2.3.2
  4. 2026-05-25 Version 2.3.1 ~ Fixed: security. 2.3.1
  5. 2026-03-11 Version 2.3.0 ~ Fixed: security. 2.3.0
  6. 2026-02-06 Version 2.2.9 ~ Fixed: security. ~ Update: layout checkout page. 2.2.9

Known vulnerabilities

via Wordfence Intelligence

28 disclosed vulnerabilities on record for this plugin, all fixed in the current version. Sites on older versions stay exposed until they update.

  1. 2026-07-30 CVE-2026-15153 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects < 2.3.2 Patched in 2.3.2
  2. 2026-07-23 CVE-2026-15464 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.3.2 Patched in 2.3.3
  3. 2026-07-21 CVE-2026-15149 Client-Side Enforcement of Server-Side Security Affects <= 2.3.2 Patched in 2.3.3
  4. 2026-07-16 CVE-2026-15094 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.3.2 Patched in 2.3.3
  5. 2026-07-10 CVE-2026-11901 Insufficient Verification of Data Authenticity Affects <= 2.3.1 Patched in 2.3.2
  6. 2026-07-09 CVE-2026-11392 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.3.1 Patched in 2.3.2
  7. 2026-07-09 CVE-2026-15152 Insufficient Verification of Data Authenticity Affects <= 2.3.1 Patched in 2.3.2
  8. 2026-06-19 CVE-2026-9822 Missing Authorization Affects < 2.3.1 Patched in 2.3.1
  9. 2026-01-16 CVE-2025-14075 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.2.7 Patched in 2.2.8
  10. 2025-11-05 CVE-2025-63012 Cross-Site Request Forgery (CSRF) Affects <= 2.2.8 Patched in 2.2.9
  11. 2025-11-05 CVE-2025-63013 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 2.2.7 Patched in 2.2.8
  12. 2025-11-05 CVE-2025-63011 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 2.2.8 Patched in 2.2.9
  13. 2025-08-28 CVE-2025-8942 Missing Authorization Affects <= 2.2.2 Patched in 2.2.3
  14. 2025-05-07 CVE-2025-47448 Cross-Site Request Forgery (CSRF) Affects <= 2.1.9 Patched in 2.2.0
  15. 2025-01-21 CVE-2024-13447 Missing Authorization Affects <= 2.1.6 Patched in 2.1.7
  16. 2025-01-16 CVE-2024-12370 Improper Access Control Affects <= 2.1.5 Patched in 2.1.6
  17. 2024-10-31 CVE-2024-51582 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Affects <= 2.2.9 Patched in 2.3.0
  18. 2024-10-01 CVE-2024-7855 Unrestricted Upload of File with Dangerous Type Affects <= 2.1.2 Patched in 2.1.3
  19. 2024-06-19 CVE-2024-3605 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.1.0 Patched in 2.1.1
  20. 2024-03-28 CVE-2024-30508 Missing Authorization Affects <= 2.0.9.2 Patched in 2.0.9.3
  21. 2024-02-03 Improper Authorization Affects <= 2.0.9.2 Patched in 2.0.9.3
  22. 2023-10-26 CVE-2023-5799 Incorrect Authorization Affects <= 2.0.8 Patched in 2.0.9
  23. 2023-10-26 CVE-2023-5652 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 2.0.7 Patched in 2.0.8
  24. 2023-10-20 CVE-2023-5651 Missing Authorization Affects <= 2.0.7 Patched in 2.0.8
  25. 2022-08-22 Missing Authorization Affects <= 2.0.0 Patched in 2.0.1
  26. 2022-08-02 CVE-2021-36852 Cross-Site Request Forgery (CSRF) Affects <= 1.10.5 Patched in 1.10.6
  27. 2020-12-08 CVE-2020-29047 Deserialization of Untrusted Data Affects <= 1.10.3 Patched in 1.10.4
  28. 2020-09-16 CVE-2020-36757 Cross-Site Request Forgery (CSRF) Affects < 1.10.2 Patched in 1.10.2

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Behavioral tests

via WP Hive

Automated install-time checks, tested on PHP 8.1.12 · WP 7.0.1

Low memory footprint
Low page-speed impact
Runs on latest PHP + WP
No PHP errors
No JS errors
Activates cleanly
No resource errors
No external HTTP errors
Optimized database use
Frequently updated

Languages

via translate.wordpress.org

Translated into 13 languages, 0 at 90% or more

Russian 76%
Bulgarian 69%
Japanese 65%
Italian 59%
Swedish 51%
Polish 50%
French (France) 49%
Ukrainian 49%
Albanian 45%
Dutch 31%
Czech 6%
German 2%
Spanish (Mexico) 2%

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

  1. 2026-06-19 8K+ → 7K+ down after 666 days in tier
  2. 2024-08-22 9K+ → 8K+ down after 480 days in tier
  3. 2023-04-30 10K+ → 9K+ down

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for WP Hotel Booking into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/wp-hotel-booking" width="480" height="300" style="border:0" loading="lazy" title="WP Hotel Booking — Plugin Pulse"></iframe>
Preview card ↗

WP Hotel Booking: 7K+ active installs, 3.7★ (67 reviews). Plugin Pulse (WP Mayor), as of 2026-08-25. https://plugins.wpmayor.com/plugin/wp-hotel-booking