Car Route Planner Plugin Security & Risk Analysis

wordpress.org/plugins/car-route-planner

Route planner for car travelers. Calculator of various values for route, such as length, driving time, fuel amount and cost, customized cost.

400 active installs v1.7 PHP 5.3+ WP 4.2+ Updated Feb 5, 2024
calculatordirectiondistanceroutetravel
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Car Route Planner Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

Car Route Planner Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The 'car-route-planner' v1.7 plugin exhibits a mixed security posture. While the absence of known CVEs and a complete lack of taint analysis findings are positive indicators, the static analysis reveals significant areas for improvement. The plugin has a concerningly low rate of proper output escaping (38%), suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities. The lack of any nonce or capability checks on its entry points, coupled with an absence of AJAX handlers, REST API routes, shortcodes, and cron events, is noteworthy. This could indicate a very limited functionality or, conversely, a blind spot in the analysis. The presence of file operations and an external HTTP request warrants further scrutiny, as these can be vectors for compromise if not handled securely. Overall, the plugin's lack of historical vulnerabilities is a strength, but the identified static analysis weaknesses, particularly in output escaping and authorization checks, present a notable risk that should not be overlooked.

Key Concerns

  • Low output escaping rate
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Car Route Planner Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Car Route Planner Plugin Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Car Route Planner Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
80
49 escaped
Nonce Checks
0
Capability Checks
0
File Operations
2
External Requests
1
Bundled Libraries
0

Output Escaping

38% escaped129 total outputs
Attack Surface

Car Route Planner Plugin Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitblock\car-route-planner-block.php:21
actionplugins_loadedcar-route-planner.php:25
actionadmin_initcar-route-planner.php:30
actionadmin_menucar-route-planner.php:31
actionupgrader_process_completecar-route-planner.php:34
filterplugin_action_linksclass.car-route-planner-admin.php:8
actionadmin_noticesclass.car-route-planner-admin.php:10
Maintenance & Trust

Car Route Planner Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedFeb 5, 2024
PHP min version5.3
Downloads13K

Community Trust

Rating60/100
Number of ratings10
Active installs400
Developer Profile

Car Route Planner Plugin Developer Profile

iGuk

2 plugins · 460 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Car Route Planner Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/car-route-planner/class.car-route-planner.php/wp-content/plugins/car-route-planner/class.car-route-planner-admin.php/wp-content/plugins/car-route-planner/block/car-route-planner-block.php/wp-content/plugins/car-route-planner/js/clipboard.min.js/wp-content/plugins/car-route-planner/js/autocomplete.js/wp-content/plugins/car-route-planner/js/admin.js/wp-content/plugins/car-route-planner/css/admin.css
Script Paths
wp-content/plugins/car-route-planner/js/clipboard.min.jswp-content/plugins/car-route-planner/js/autocomplete.jswp-content/plugins/car-route-planner/js/admin.js

HTML / DOM Fingerprints

CSS Classes
crp-wrapcrp-config-choice-simplecrp-config-choice-advanced
Data Attributes
id="crp-options-form"name="crp_shortcode_type"value="simple"id="crp-simple-config"value="advanced"id="crp-advanced-config"
JS Globals
CarRoutePlannerCarRoutePlannerAdmin
Shortcode Output
[car-route-planner]
FAQ

Frequently Asked Questions about Car Route Planner Plugin