
Facilitated Routines Security & Risk Analysis
wordpress.org/plugins/facilitated-routinesAutomate technical SEO, image optimization and webp creation, security, unused media cleanup, sitemaps, find broken links, and more.
Is Facilitated Routines Safe to Use in 2026?
Generally Safe
Score 100/100Facilitated Routines has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The facilitated-routines plugin version 2.6.47 exhibits a mixed security posture. On the positive side, it demonstrates a strong adherence to secure coding practices by exclusively using prepared statements for all SQL queries and performing a significant number of nonce and capability checks. The absence of known vulnerabilities and past CVEs further suggests a generally stable and well-maintained codebase.
However, several concerns warrant attention. The plugin exposes a considerable attack surface with 30 AJAX handlers, 13 of which lack authentication checks. While no critical or high severity taint flows were identified, the presence of 3 flows with unsanitized paths, even if of lower severity, indicates a potential for injection vulnerabilities if these paths are user-controlled. Furthermore, only 51% of output is properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities in specific scenarios where user-provided data is not adequately sanitized before being displayed.
In conclusion, while the plugin benefits from good SQL hygiene and a clean vulnerability history, the large number of unprotected AJAX endpoints and partially unescaped output represent the most significant security risks. Addressing these areas should be prioritized to improve the overall security of the plugin.
Key Concerns
- 13 unprotected AJAX handlers
- 51% of outputs properly escaped
- 3 flows with unsanitized paths
Facilitated Routines Security Vulnerabilities
Facilitated Routines Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Facilitated Routines Attack Surface
AJAX Handlers 30
WordPress Hooks 64
Maintenance & Trust
Facilitated Routines Maintenance & Trust
Maintenance Signals
Community Trust
Facilitated Routines Alternatives
QuickWebP – Compress / Optimize Images & Convert WebP | SEO Friendly
quickwebp
QuickWebP is a free WordPress plugin that converts images to WebP, optimizes performance, improves SEO, auto-fills metadata, and resizes images—no API …
Auto Image Title & Alt
auto-image-title-alt
Automatically adds title and alt tags to new images in the media library, improving SEO and accessibility with customizable fields and capitalization.
Soovex WebP Converter – Convert Images | Optimize & Compress | Unlimited Conversions
soovex-webp-converter
Automatically convert WordPress images to WebP format. Optimize images, boost page speed and SEO with unlimited conversions and smart backups.
WhereUsed
where-used
Where used? This plugin helps you find usage of attachments, posts, links, blocks and more in all post types, taxonomy terms, post meta, user meta, an …
Image Squeeze – Optimize WebP, Compress Images, Boost Performance
imagesqueeze
Smart image optimization for WordPress. Compress, convert to WebP, and speed up your site while improving Core Web Vitals and SEO.
Facilitated Routines Developer Profile
1 plugin · 70 total installs
How We Detect Facilitated Routines
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/facilitated-routines/includes/js/ui.js/wp-content/plugins/facilitated-routines/includes/js/ui.jsfacilitated-routines/includes/js/ui.js?ver=HTML / DOM Fingerprints
FacilitatedRoutines