shouldiuse.io

VERDICT

Should I use Wpamelia (Amelia WordPress Booking Plugin)?

Grow Your Business This Fall - wpamelia.com

Depends. Buy it if you run a salon, clinic, or multi-staff service business already on WordPress and need built-in booking. Avoid it if you're not on WordPress, want a simple Calendly-style link, or won't stay on top of urgent security patches.

Confidence

Medium. Based on ~35 public sources including CVE databases, Reddit, Trustpilot, and vendor pages; exact paid prices and Trustpilot rating not shown in reviewed snippets.

Ratings

  • Value for money
  • Ease of use
  • Feature depth
  • Support quality
  • Security posture

Pricing

Free

Lite

ModelNot disclosed
Monthly feesNot disclosed
HardwareNot disclosed
Free tierYes
Paid plansNot published in reviewed sources

Best for

  • Salons and barbershops on WordPress
  • Clinics and med spas
  • Multi-staff service businesses
  • Tutors and consultants booking clients

Not for

  • Non-WordPress sites — it's a plugin, full stop
  • Anyone wanting a dead-simple Calendly-style link
  • Teams that won't patch WordPress plugins fast
  • Enterprises needing dedicated scheduling infrastructure

Gotchas - check before you buy

high

Unpatched sites exposed to active privilege-escalation CVEs; update within days of releases

medium

Cancellation reportedly hard to find; third-party step-by-step cancel guides exist

medium

Reddit reports upgrade problems moving from free to paid versions

medium

Guess: bookings live in your WordPress database; migrating to SaaS schedulers means manual export

Pros and cons

Pros

  • Booking for appointments, events, and resources natively inside WordPress
  • Free Lite version available on
  • Official staff mobile app on Google Play
  • Recommended by users in r/Wordpress booking threads
  • 15-day money-back guarantee on paid plans

Cons

  • Multiple critical 2026 CVEs, including unauthenticated privilege escalation
  • SQL injection vulnerability disclosed April 2026
  • Zero verified reviews on vendor's G2 seller profile
  • Vendor's own comparison highlights Calendly's stronger ease of use

Sources & method

Analyzed 9/26/2026 - 14 sources - Rough 2026: four CVEs including a critical unauthenticated privilege escalation — patch discipline is mandatory.

official x3review x6security x5
  • CVE-2026-9055 — unauthenticated privilege escalation, Unauthenticated attacker can escalate to the wpamelia-manager role; disclosed September 2026.
  • CVE-2026-14782 — authenticated privilege escalation, Authenticated customer-to-admin password reset via IDOR; disclosed July 2026.
  • CVE-2026-4668 — SQL injection, SQL injection vulnerability affecting the Amelia plugin; disclosed April 2026.
  • Sensitive data disclosure, Researcher documented a sensitive data exposure flaw in the Amelia plugin.

Key stats

  • Value for money: 3/5

    Rating

  • Free

    Starting price

  • 14

    Sources

  • Analyzed

  • Value for money: 3/5. Free tier and money-back guarantee; prices not shown in sources
  • Ease of use: 2/5. Vendor's own comparison highlights Calendly's 9.4/10 ease edge
  • Feature depth: 4/5. Broad booking suite; competitor review tested 37 features
  • Support quality: 3/5. Self-reported support award; active ticket forum
  • Security posture: 1/5. Four 2026 CVEs including critical privilege escalation
  • 257 Trustpilot reviews wpamelia.com reviews
  • Yes Free tier Lite version on WordPress.org
  • 4 2026 CVEs incl. critical privilege escalation and SQLi
  • 0 reviews G2 seller rating TMS-Plugins unrated on G2

Pricing

Lite

Free

  • Basic booking via WordPress.org
  • Community support

Paid plans

Not published in reviewed sources

  • Full appointment, event, and payments features
  • 15-day money-back guarantee

Security

Rough 2026: four CVEs including a critical unauthenticated privilege escalation — patch discipline is mandatory.

  • CVE-2026-9055 — unauthenticated privilege escalationUnauthenticated attacker can escalate to the wpamelia-manager role; disclosed September 2026.⁹
  • CVE-2026-14782 — authenticated privilege escalationAuthenticated customer-to-admin password reset via IDOR; disclosed July 2026.11
  • CVE-2026-4668 — SQL injectionSQL injection vulnerability affecting the Amelia plugin; disclosed April 2026.10
  • Sensitive data disclosureResearcher documented a sensitive data exposure flaw in the Amelia plugin.

What users say

WordPress community users broadly recommend Amelia as a turnkey booking solution; Trustpilot shows 257 reviews while the vendor's G2 profile shows zero.

“I have used and can recommend”
Reddit, r/Wordpress
“Checkout https://wpamelia.com/ for an actual turnkey appointment schedule system”
Reddit, r/Wordpress

Alternatives

Compare Wpamelia (Amelia WordPress Booking Plugin) with each alternative.

Full analysis

Based on ~35 public sources including CVE databases, Reddit, Trustpilot, and vendor pages; exact paid prices and Trustpilot rating not shown in reviewed snippets.

Capable WordPress booking plugin for salons and clinics — but four 2026 CVEs demand fast patching. Not for non-WP sites.

Methodology

Based on ~35 public sources including CVE databases, Reddit, Trustpilot, and vendor pages; exact paid prices and Trustpilot rating not shown in reviewed snippets.

Sources

  1. official
  2. Amelia Pricingwpamelia.com
    official
  3. review
  4. review
  5. review
  6. review
  7. review
  8. review
  9. security
  10. security
  11. security
  12. security
  13. official
  14. security

Rate this review

Anonymous. You can change your vote.

Loading votes…

Comments

One queue. No nested comments. Give a display name first. Limit: 200 words per comment and 7 comments per day. You can edit or delete yours.

Save a name to write a comment.

0 / 200 words

No comments yet.