shouldiuse.io

VERDICT

Should I use Calendarista?

Run bookings on your own WordPress site — and from your phone. Every Calendarista plugin includes the same iPhone and Android app at no extra cost, with payments, automated confirmations and no per-booking fees. - calendarista.com

Depends. Buy if you run a WordPress site, want flat-fee bookings with a bundled mobile app, and will keep the plugin patched. Skip if you can't manage security updates or need dependable support from a larger vendor.

Confidence

Medium. Based on ~20 public sources; exact paid tier prices not exposed in reviewed pages.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

Free (WordPress.org)

Basic Edition

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Premium EditionNot disclosed in sources
SoloNot disclosed in sources

Best for

  • WordPress site owners taking appointments
  • Solo salons, clinics, tee-time scheduling
  • Buyers wanting flat pricing, no per-booking fees
  • Users wanting a bundled mobile app

Not for

  • Non-WordPress sites — it only works inside WP
  • Teams without discipline to patch plugin CVEs fast
  • Anyone needing enterprise-grade vendor support
  • Buyers expecting reliable set-and-forget calendar sync

Gotchas - check before you buy

high

Outdated installs are exposed to known CVEs; patch immediately or risk auth bypass and SQL injection.

medium

Contact Form 7 PayPal/Stripe add-on conflict reportedly broke customer checkouts.

medium

Recurring bookings may not show in Google Calendar sync, per user reports.

low

Trustpilot shows only one review — real-world satisfaction data is thin.

Pros and cons

Pros

  • iPhone and Android app included free with every edition
  • No per-booking fees; flat one-price model
  • Payments and automated confirmations built in
  • Positioned as all-features-included rival to Bookly, Amelia, Booknetic
  • Recommended by Reddit users for golf tee-time scheduling

Cons

  • 2.5/5 average rating on reviews
  • Four CVEs in 2024, including SQL injection and auth bypass
  • Recurring Google Calendar sync problems reported
  • Very small vendor (~1 employee) per public data
  • Reviewed as 'capable, but no longer the smart buy'

Sources & method

Analyzed 9/24/2026 - 12 sources - Four 2024 CVEs disclosed — run the latest version or risk known exploits.

official x2review x6security x3news x1
  • CVE-2024-30534: Missing authorization / auth bypass, Broken access control in Calendarista Basic Edition; missing authorization vulnerability.
  • CVE-2024-30240: SQL injection, Calendarista affected by SQL injection vulnerability.
  • CVE-2024-31942: Cross-site request forgery, CSRF vulnerability in Calendarista Basic Edition.
  • CVE-2024-27993: Improper neutralization, Cross-site scripting issue in Typps Calendarista Basic Edition plugin.

Key stats

  • Value for money: 3/5

    Rating

  • Free (WordPress.org)

    Starting price

  • 12

    Sources

  • Analyzed

  • Value for money: 3/5. Flat pricing, no per-booking fees; judged no longer smart buy
  • Ease of use: 2/5. 2.5/5 rating; setup and sync complaints
  • Feature depth: 4/5. Payments, confirmations, mobile app in every edition
  • Support quality: 2/5. ~1-employee vendor; unresolved conflict reports
  • Security posture: 1/5. Four 2024 CVEs including SQL injection
  • 2.5/5 WordPress.org rating Basic Edition reviews
  • 4 Known CVEs (2024) Incl. SQL injection and auth bypass
  • 3 Pricing plans Basic, Premium, Solo
  • ~1 employee Vendor size Per public company data

Pricing

Basic Edition

Free (WordPress.org)

  • Appointment booking on WordPress
  • Mobile app included

Premium Edition

Not disclosed

  • All features, one price
  • Mobile app included

Solo

Not disclosed

  • Take bookings, get paid
  • Mobile app included

Security

Four 2024 CVEs disclosed — run the latest version or risk known exploits.

  • CVE-2024-30534: Missing authorization / auth bypassBroken access control in Calendarista Basic Edition; missing authorization vulnerability.⁶
  • CVE-2024-30240: SQL injectionCalendarista affected by SQL injection vulnerability.⁷
  • CVE-2024-31942: Cross-site request forgeryCSRF vulnerability in Calendarista Basic Edition.
  • CVE-2024-27993: Improper neutralizationCross-site scripting issue in Typps Calendarista Basic Edition plugin.

Companies that use it

  • Potager Garden
Full analysis

Based on ~20 public sources; exact paid tier prices not exposed in reviewed pages.

Capable WP booking plugin with free bundled app and no per-booking fees — but 2.5/5 reviews, four 2024 CVEs, ~1-person vendor.

Methodology

Based on ~20 public sources; exact paid tier prices not exposed in reviewed pages.

Sources

  1. official
  2. review
  3. review
  4. official
  5. review
  6. security
  7. security
  8. review
  9. review
  10. news
  11. security
  12. review

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.