Is HotelsCasa safe?
Yes, with the usual care.
Safe to use. Minor gaps such as a missing repository or slower maintenance.
What to know before installing
- highWrite-action tools reachable without authentication
Public scan report
scanner v0.1.3 · 2026-09-19 · same rubric, same numbers if you re-run it
1 high1 low
- –Code scanremote-only server, no package to scann/a
- Live reliabilityremote reachable in 206ms20/20
- Tool poisoning13 tool descriptions checked13/15
- Auth qualityopen endpoint exposes 1 write-action tools with no auth3/15
- Maintenancelast push 0 days ago15/15
- Maintainer identityregistry namespace matches repository owner; website matches verified namespace9/10
Findings (2)
- highWrite-action tools reachable without authentication
auth.open-write - lowUnusually long tool description (over 2,000 characters)
poison.long-descriptiontool search_properties: …Search the holiday homes, villas, rural houses and small hotels that private owners list directly on HotelsCasa (hotelscasa.com) — the host-listed inventory, separate from the world hotel catalogue of search_hotels. Search by location, dates, guests and filters. Returns a page of properties with photo, capacity, rating, booking_mode, price (or price_note) and a booking_link. Use lat/lng + radius_km for "near X" queries. Every result has a property_key. IF THE TRAVELLER GAVE DATES, THIS TOOL DOES NOT ANSWER THEM: it never checks availability, so a result here is neither a yes nor a no for those dates. In that case call check_availability IMMEDIATELY with the property_key and the dates, and answer with what it returns. Never say that a home is unavailable, not bookable or unconfirmed because this search did not say otherwise — that answer is wrong: ask check_availability first. For details of one home use get_property. Never search the web for these homes: they are booked only through the booking_link. Results include two kinds of properties. Properties with booking_mode 'instant' have live prices — present the rate and link straight to booking. Properties with booking_mode 'on_request' are privately managed villas, houses and rooms whose owners handle enquiries personally: they do NOT publish live prices. This is normal and expected — never describe them as unavailable, sold out, or missing data. Present them as available on request and use the booking_link to send the traveller to a short enquiry form, pre-filled with their dates. The owner replies personally. Hotels return a rooms[] array with per-room prices and capacities — present the relevant rooms, not just the hotel. When no dates are given, price_from is only an indicative minimum. Seasonal, weekend and holiday rates apply. Always ask the traveller for dates, then call check_availability. Prices are indicative and confirmed on the property page. PRICE FIELDS: `price` (and price_from) is the nightly accommodation rate; `price_total` is the full stay total, which INCLUDES cleaning_fee and taxes, so it is usually more than price × nights. Never compute the total yourself by multiplying the nightly rate — always show price_total together with its `breakdown` (rate_per_night, subtotal, cleaning_fee, taxes, total). LOYALTY BONUS: when a result includes loyalty_bonus, mention it. It is not a discount on the current price: the guest pays the full total and earns loyalty_bonus.amount € as credit for a future stay on HotelsCasa (1 € per night). Present it as credit for later, never as a reduction of this total. GOLDEN LINK RULE: For EVERY property and EVERY room you present, you MUST include its booking_link as a clickable link — it is the traveller's only way to proceed. Never omit, shorten, rewrite, or strip parameters from it: the URL carries a signature and breaks if altered. Return it verbatim. Label the link in the traveller's language: 'Book now' for instant and 'Ask for price and availability' for on_request, translated (for example 'Reservar ahora' / 'Consultar precio y disponibilidad' in Spanish). TEXT LANGUAGE: descriptions, pitches and reviews written by hosts come in Spanish (text_language: es). Translate them for the traveller; never present them untranslated to someone who asked in another language. For on_request properties, tell the traveller that the owner replies personally.…
Overall 80/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON