Plugin Pulse
← Pulse

WPBookit

by Iqonic Design · Booking & Events

Also makes 5 other plugins · 15.1K+ installs across the portfolio →

WPBookit is a free WordPress booking plugin that simplifies seamless scheduling, custom calendars and global accessibility.

⚠ Few reviews⚠ Open vulnerability
How scoring works →
Not scored
Maintenance 83/100
Rating quality no data
Support no data
Security 0/100

Not scored yet. Nobody has reviewed this plugin, so a grade would come from directory averages rather than from anything measured here.

Install conversion

How it's measured →

0.2%

of downloads still active

At least 10 of 4.9K lifetime downloads are still running, below its category: the median Booking & Events plugin keeps 0.8%, across 902 plugins.

Downloads count every update, not just first installs, so older and more frequently released plugins read lower. Compare against other Booking & Events plugins, not across the directory. wp.org reports active installs as the bottom of a band, so the real rate is this or higher.

Directory ranking optimization

How it's scored →

How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.

84 / 100

Well optimized

Most to gain: Rating quality

Update recency 94/100
WP compatibility 100/100
Rating quality 49/100
Listing tuning 92/100

To rank higher: No reviews yet. wp.org scores an unrated plugin as middling on rating, so the first good reviews lift it.

Get the full rank-higher report →

Daily downloads

Since 2024-12-04 · 659 days · wp.org + Plugin Pulse archive

+36% vs prior 30d
5Downloads · Sep 26

30-day downloads

Rolling 30-day volume · peaks are release surges

250

now · peak 259

25030d downloads · Sep 24

Update activity

How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.

25Kper 1k installs · Sep 24

Estimated active installs

The public count shows “10+”. Our estimate pins where the real number sits.

modeled estimate
10–20 ≈17

Modeled within the band wp.org reports; tightens as we track daily.

Install history · since 2026-09-23 · 2 observations

10Installs · Sep 24

Estimated value

What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.

Est. annual revenue

N/A

Est. acquisition value

N/A

No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from.

Details

Version
1.0.9
Last updated
7mo ago
Added
2024-12-18 · 1 yr old
Requires WP
3.0.1
Tested up to
6.9.9
Requires PHP
8.0

Known vulnerabilities

via Wordfence Intelligence

14 disclosed vulnerabilities on record for this plugin, 4 still affect the current version.

  1. 2026-03-03 CVE-2026-1945 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.0.8 Patched in 1.0.9
  2. 2026-03-03 CVE-2026-1980 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 1.0.8 Patched in 1.0.9
  3. 2025-12-12 CVE-2025-12685 Cross-Site Request Forgery (CSRF) Affects <= 1.0.7 No patch available
  4. 2025-11-20 CVE-2025-12135 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.0.6 Patched in 1.0.7
  5. 2025-07-23 CVE-2025-7852 Unrestricted Upload of File with Dangerous Type Affects <= 1.0.6 Patched in 1.0.7
  6. 2025-07-11 CVE-2025-6058 Unrestricted Upload of File with Dangerous Type Affects <= 1.0.4 Patched in 1.0.5
  7. 2025-07-11 CVE-2025-6057 Unrestricted Upload of File with Dangerous Type Affects <= 1.0.4 Patched in 1.0.5
  8. 2025-05-08 CVE-2025-3810 Authorization Bypass Through User-Controlled Key Affects <= 1.0.2 Patched in 1.0.3
  9. 2025-05-08 CVE-2025-3811 Authorization Bypass Through User-Controlled Key Affects <= 1.0.2 Patched in 1.0.3
  10. 2025-04-04 CVE-2025-32254 Missing Authorization Affects <= 1.0.7 Patched in 1.0.8
  11. 2025-03-09 CVE-2025-26910 Cross-Site Request Forgery (CSRF) Affects <= 1.0.1 Patched in 1.0.2
  12. 2025-01-24 CVE-2025-0357 Unrestricted Upload of File with Dangerous Type Affects <= 1.6.9 Patched in 1.6.10
  13. 2025-01-09 CVE-2024-10215 Authorization Bypass Through User-Controlled Key Affects <= 1.6.4 Patched in 1.6.6
  14. 2024-12-11 CVE-2024-54280 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.6.0 No patch available

Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.

CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.

Growth timeline

Install-tier crossings we have observed, and how long each tier took to outgrow

No tier crossings observed yet.

Competes with

The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).

Compare head to head →

Embed this report card

Drop a live Pulse card for WPBookit into a readme, a review or a deck. It updates itself.

<iframe src="https://plugins.wpmayor.com/embed/wpbookit" width="480" height="300" style="border:0" loading="lazy" title="WPBookit — Plugin Pulse"></iframe>
Preview card ↗

WPBookit: 10+ active installs, no reviews yet. Plugin Pulse (WP Mayor), as of 2026-09-24. https://plugins.wpmayor.com/plugin/wpbookit