shouldiuse.io

Categories

VERDICT

Should I use Bookly?

Bookly is a WordPress booking plugin trusted by 60,000+ businesses. Automate appointments, payments, and reminders. Free, Pro from $39/year or $99 lifetime. - booking-wp-plugin.com

Depends. Buy if your site runs WordPress and you will apply security patches promptly — it is cheap and widely used. Skip it if you handle sensitive client data or won't maintain a plugin; the CVE history is serious.

Confidence

Medium. Based on ~25 public sources. Several review results referred to an unrelated 'Bookly' reading-tracker app and were excluded from this WordPress plugin analysis.

Ratings

  • Value for money
  • Ease of useNo reliable evidence in sources
  • Feature depth
  • Support qualityNo support-quality evidence in sources
  • Security posture

Pricing

$0

Free

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Pro$39/yr or $99 lifetime

Best for

  • WordPress sites needing native booking
  • Solo service businesses (salons, tutors, clinics)
  • Budget owners wanting a lifetime license
  • Teams avoiding per-seat SaaS scheduling fees

Not for

  • Non-WordPress websites — entirely wrong tool
  • Owners who won't patch security updates promptly
  • Clinics handling sensitive client data (SQLi and info-disclosure history)
  • Buyers wanting zero-maintenance hosted booking

Gotchas - check before you buy

high

Unauthenticated SQL injection CVE-2026-61949 — update immediately; real data-exposure risk.

high

Auth bypass CVE-2026-2520; older installs remain exposed.

medium

No vendor security page — track advisories via Wordfence/NVD yourself.

medium

Pricing model changed over time; verify current tier contents before paying.

Pros and cons

Pros

  • Free core plugin; Pro from $39/year or $99 lifetime.
  • Trusted by 60,000+ businesses; 3.5M+ downloads.
  • SMS, WhatsApp, and customer-cabinet add-ons extend features.
  • 30-day money-back guarantee on paid plans.
  • Positioned as WordPress-native Calendly alternative.

Cons

  • Repeated 2026 CVEs: auth bypass, unauthenticated SQL injection, data exposure.
  • Vendor site shows no dedicated security page.
  • Pricing has shifted ($89 paid before; now free/$39), confusing longtime users.
  • SMS and WhatsApp notifications cost extra.
  • Useful features gated behind paid Pro add-ons.

Sources & method

Analyzed 9/24/2026 - 14 sources - Poor track record: 8 CVEs in reviewed sources, including unauthenticated SQL injection and auth bypass; vendor site shows no security page.

official x4review x5security x5
  • CVE-2026-2520 — Auth Bypass, Authentication bypass flaw in the Bookly WordPress plugin.
  • CVE-2026-61949 — SQL Injection, Unauthenticated SQL injection vulnerability disclosed for Bookly.
  • CVE-2026-42667 — Sensitive Data Exposure, Unauthenticated sensitive data exposure in Bookly.
  • CVE-2026-89063 — Information Disclosure, Information disclosure flaw in the Bookly plugin.
  • Bookly 2.7.4 — Unauthenticated Info Exposure, Wordfence advisory for information exposure in Bookly 2.7.4.

Key stats

  • Value for money: 4/5

    Rating

  • $0

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money: 4/5. $39/yr or $99 lifetime undercuts SaaS rivals
  • Ease of use. No reliable evidence in sources
  • Feature depth: 4/5. Add-ons: SMS, WhatsApp, customer cabinet, payments
  • Support quality. No support-quality evidence in sources
  • Security posture: 1/5. Eight CVEs including unauthenticated SQL injection
  • 60,000+ Businesses using per vendor
  • $39/yr Starting price Pro; $99 lifetime option
  • Yes Free tier core plugin is free
  • 8 Public CVEs found in security sources reviewed

Pricing

Free

$0

  • Core booking and scheduling
  • Limited add-on features

Pro

$39/yr or $99 lifetime

  • Payments, reminders, customer cabinet
  • SMS/WhatsApp via paid add-ons

Security

Poor track record: 8 CVEs in reviewed sources, including unauthenticated SQL injection and auth bypass; vendor site shows no security page.

  • CVE-2026-2520 — Auth BypassAuthentication bypass flaw in the Bookly WordPress plugin.10
  • CVE-2026-61949 — SQL InjectionUnauthenticated SQL injection vulnerability disclosed for Bookly.11
  • CVE-2026-42667 — Sensitive Data ExposureUnauthenticated sensitive data exposure in Bookly.12
  • CVE-2026-89063 — Information DisclosureInformation disclosure flaw in the Bookly plugin.
  • Bookly 2.7.4 — Unauthenticated Info ExposureWordfence advisory for information exposure in Bookly 2.7.4.13

What users say

Small-business reviewers call Bookly a solid WordPress-native Calendly alternative, while longtime users grumble about shifting pricing.

“Is Bookly free now? I remember paying $89”
Reddit, r/Wordpress
“Bookly is a smart choice”
SchedulingKit review

Companies that use it

  • Premier Hormone
Full analysis

Based on ~25 public sources. Several review results referred to an unrelated 'Bookly' reading-tracker app and were excluded from this WordPress plugin analysis.

Cheap, popular WordPress booking plugin — but a stack of 2026 CVEs means patch religiously or pick a hosted tool.

Methodology

Based on ~25 public sources. Several review results referred to an unrelated 'Bookly' reading-tracker app and were excluded from this WordPress plugin analysis.

Sources

  1. official
  2. Bookly Pricing Plansbooking-wp-plugin.com
    official
  3. official
  4. Bookly vs Calendly 2026booking-wp-plugin.com
    official
  5. review
  6. review
  7. review
  8. review
  9. Bookly on Capterracapterra.com
    review
  10. security
  11. CVE-2026-61949 SQL Injectioncve.halosecurity.com
    security
  12. security
  13. security
  14. security

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.