Boat Tracker Security & Risk Analysis
wordpress.org/plugins/boat-trackerTrack your boat around the globe with Iridium, AIS, InReach, PredictWind, SPOT, Startlink, etc, and display an interactive map on your website.
Is Boat Tracker Safe to Use in 2026?
Generally Safe
Score 92/100Boat Tracker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "boat-tracker" plugin version 1.0.0 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and 100% proper output escaping are excellent security practices. Furthermore, the plugin demonstrates good security awareness with the presence of nonce and capability checks, and a minimal attack surface consisting of a single shortcode without any identified unprotected entry points. The vulnerability history is also clean, with no known CVEs, indicating a potentially well-maintained codebase or a lack of past security incidents. This suggests a low immediate risk profile.
However, a single flow with unsanitized paths identified during taint analysis, despite not being classified as critical or high severity in this specific instance, warrants attention. While the current analysis indicates no immediate exploitation risk from this flow, it represents a potential weakness that could be exploited under different circumstances or if combined with other vulnerabilities. The fact that this is the only taint flow analyzed suggests the analysis scope might be limited. The plugin's limited functionality and attack surface also contribute to its current strong security standing. Overall, the plugin is well-developed from a security perspective, but the identified unsanitized path flow, however minor in this context, represents the sole deviation from an otherwise impeccable security report.
Key Concerns
- Flow with unsanitized paths
Boat Tracker Security Vulnerabilities
Boat Tracker Release Timeline
Boat Tracker Code Analysis
Output Escaping
Data Flow Analysis
Boat Tracker Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Boat Tracker Maintenance & Trust
Maintenance Signals
Community Trust
Boat Tracker Alternatives
iframe
iframe
[iframe src="http://www.youtube.com/embed/7_nAZQt9qu0" width="100%" height="500"] shortcode
Embed Code – Headers & Footers by DesignBombs
embed-code
The easiest way to embed code in the head or footer of your site, globally or on a per-page/post basis.
Sch.gr Commons
schgr-commons
Just copy/paste a URL of video from https://video.sch.gr, or a school location map from https://maps.sch.gr into your WordPress posts and see them emb …
Embed Extended – Embed Maps, Videos, Websites, Source Codes, and more
embed-extended
Embed any external content into WordPress posts and pages. It works seamlessly on Gutenberg, Elementor, classic editor, the embed shortcode, as well a …
Trackserver
trackserver
GPS Track Server for TrackMe, OruxMaps and others
Boat Tracker Developer Profile
1 plugin · 10 total installs
How We Detect Boat Tracker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/boat-tracker/style.cssboat-tracker/style.css?ver=HTML / DOM Fingerprints
boat-tracker-map<!-- Boat Tracker Plugin -->data-boat-tracker-settingsboatTrackerMap/wp-json/boat-tracker/v1/tracks[boat_tracker_map]