WPBookit
by Iqonic Design · Booking & Events
Also makes 5 other plugins · 15.1K+ installs across the portfolio →
WPBookit is a free WordPress booking plugin that simplifies seamless scheduling, custom calendars and global accessibility.
Not scored yet. Nobody has reviewed this plugin, so a grade would come from directory averages rather than from anything measured here.
Install conversion
How it's measured →0.2%
of downloads still active
At least 10 of 4.9K lifetime downloads are still running, below its category: the median Booking & Events plugin keeps 0.8%, across 902 plugins.
Downloads count every update, not just first installs, so older and more frequently released plugins read lower. Compare against other Booking & Events plugins, not across the directory. wp.org reports active installs as the bottom of a band, so the real rate is this or higher.
Directory ranking optimization
How it's scored →How well this listing is tuned to rank in WordPress.org search, on the factors an owner controls. Not popularity, optimization.
Well optimized
Most to gain: Rating quality
To rank higher: No reviews yet. wp.org scores an unrated plugin as middling on rating, so the first good reviews lift it.
Get the full rank-higher report →Daily downloads
Since 2024-12-04 · 659 days · wp.org + Plugin Pulse archive
30-day downloads
Rolling 30-day volume · peaks are release surges
250
now · peak 259
Update activity
How busy the existing users are, measured as downloads in the last 30 days for every 1,000 active sites. A spike means a new release everyone's pulling; a long, slow decline means an aging user base that updates less.
Estimated active installs
The public count shows “10+”. Our estimate pins where the real number sits.
Modeled within the band wp.org reports; tightens as we track daily.
Install history · since 2026-09-23 · 2 observations
Estimated value
What this plugin might earn a year, and what it might sell for. Modeled from public signals; we don't see anyone's books.
Est. annual revenue
Est. acquisition value
No paid tier is visible, so we don't put a figure on revenue or sale value: that would be guessing. The install base is a real asset to an acquirer, just not one public data lets us price. A small install base leaves thin data to model from.
Details
Known vulnerabilities
via Wordfence Intelligence14 disclosed vulnerabilities on record for this plugin, 4 still affect the current version.
- 2026-03-03 CVE-2026-1945 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.0.8 Patched in 1.0.9
- Medium · 5.3 WPBookit <= 1.0.8 - Missing Authorization to Unauthenticated Sensitive Customer Data Exposure ↗2026-03-03 CVE-2026-1980 Exposure of Sensitive Information to an Unauthorized Actor Affects <= 1.0.8 Patched in 1.0.9
- 2025-11-20 CVE-2025-12135 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Affects <= 1.0.6 Patched in 1.0.7
- Critical · 9.8 WPBookit <= 1.0.6 - Unauthenticated Arbitrary File Upload via image_upload_handle Function ↗2025-07-23 CVE-2025-7852 Unrestricted Upload of File with Dangerous Type Affects <= 1.0.6 Patched in 1.0.7
- Critical · 9.8 WPBookit <= 1.0.4 - Unauthenticated Arbitrary File Upload ↗2025-07-11 CVE-2025-6058 Unrestricted Upload of File with Dangerous Type Affects <= 1.0.4 Patched in 1.0.5
- 2025-07-11 CVE-2025-6057 Unrestricted Upload of File with Dangerous Type Affects <= 1.0.4 Patched in 1.0.5
- Critical · 9.8 WPBookit <= 1.0.2 - Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Account Takeover ↗2025-05-08 CVE-2025-3810 Authorization Bypass Through User-Controlled Key Affects <= 1.0.2 Patched in 1.0.3
- Critical · 9.8 WPBookit <= 1.0.2 - Insecure Direct Object Reference to Unauthenticated Privilege Escalation via Email Update ↗2025-05-08 CVE-2025-3811 Authorization Bypass Through User-Controlled Key Affects <= 1.0.2 Patched in 1.0.3
- Medium · 5.3 WPBookit <= 1.0.7 - Missing Authorization ↗
- Critical · 9.8 WPBookit <= 1.6.9 - Unauthenticated Arbitrary File Upload ↗2025-01-24 CVE-2025-0357 Unrestricted Upload of File with Dangerous Type Affects <= 1.6.9 Patched in 1.6.10
- 2025-01-09 CVE-2024-10215 Authorization Bypass Through User-Controlled Key Affects <= 1.6.4 Patched in 1.6.6
- 2024-12-11 CVE-2024-54280 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') Affects <= 1.6.0 No patch available
Vulnerability records provided by Wordfence Intelligence. Copyright 2012-2026 Defiant Inc. License and terms.
CVE records: Copyright 1999-2026 The MITRE Corporation. CVE terms of use.
Growth timeline
Install-tier crossings we have observed, and how long each tier took to outgrow
No tier crossings observed yet.
Competes with
The plugins that solve the same job, ranked by shared tags then reach, closest match first. The letter on the right is each plugin's health grade (A best, F worst).
-
The Events Calendar 600K+ installs · 4.2★ B -
WP Activity Log 300K+ installs · 4.6★ B -
Simple History – Track, Log, and Audit WordPress Changes 300K+ installs · 4.9★ A
-
Appointment Booking Plugin – LatePoint | Calendar & Scheduling for WordPress 100K+ installs · 4.8★ B
-
Booking for Appointments and Events Calendar – Amelia 90K+ installs · 4.6★ B -
Event Tickets and Registration 90K+ installs · 3.6★ B
Embed this report card
Drop a live Pulse card for WPBookit into a readme, a review or a deck. It updates itself.
<iframe src="https://plugins.wpmayor.com/embed/wpbookit" width="480" height="300" style="border:0" loading="lazy" title="WPBookit — Plugin Pulse"></iframe> WPBookit: 10+ active installs, no reviews yet. Plugin Pulse (WP Mayor), as of 2026-09-24. https://plugins.wpmayor.com/plugin/wpbookit