Food Truck Locator Security & Risk Analysis

wordpress.org/plugins/food-truck-locator

Add a map of your food truck locations by date and time to keep your customers informed!

20 active installs v1.2.1 PHP 7.4+ WP 6.3+ Updated Dec 4, 2025
eventsfood-trucklocationtimetabletrack
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Food Truck Locator Safe to Use in 2026?

Generally Safe

Score 100/100

Food Truck Locator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The 'food-truck-locator' plugin v1.2.1 exhibits a generally good security posture based on the provided static analysis. The plugin demonstrates strong adherence to secure coding practices, particularly evident in its use of prepared statements for all SQL queries and a high percentage of properly escaped output. The absence of dangerous functions, file operations, and external HTTP requests further minimizes the attack surface and potential for remote code execution or data leakage.

However, there are areas for improvement. The lack of capability checks on any of the entry points is a significant concern. While the current analysis found no unsanitized taint flows, the absence of permission checks means that any authenticated user could potentially interact with the plugin's functionality, leading to information disclosure or denial of service if vulnerabilities were to be introduced in the future. The vulnerability history is currently clean, which is positive, but it does not negate the inherent risks introduced by missing permission controls.

In conclusion, 'food-truck-locator' v1.2.1 has a strong technical foundation with secure handling of database queries and output. The primary weakness lies in the missing capability checks on its entry points, which leaves it vulnerable to privilege escalation or unauthorized access if future vulnerabilities are discovered or if the functionality itself can be abused by lower-privileged users. The absence of past vulnerabilities is encouraging but should not lead to complacency regarding access control.

Key Concerns

  • No capability checks on entry points
Vulnerabilities
None known

Food Truck Locator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Food Truck Locator Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Food Truck Locator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
14 prepared
Unescaped Output
3
59 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared14 total queries

Output Escaping

95% escaped62 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<edit> (views\edit.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Food Truck Locator Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 1

authwp_ajax_save_locationincludes\FoodTruckLocator.php:28

Shortcodes 1

[foodtrucklocator] includes\FoodTruckLocator.php:27
WordPress Hooks 5
actionadmin_menuincludes\FoodTruckLocator.php:21
actionplugins_loadedincludes\FoodTruckLocator.php:23
actionadmin_initincludes\FoodTruckLocator.php:24
actionwp_enqueue_scriptsincludes\FoodTruckLocator.php:25
actionadmin_enqueue_scriptsincludes\FoodTruckLocator.php:26
Maintenance & Trust

Food Truck Locator Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 4, 2025
PHP min version7.4
Downloads2K

Community Trust

Rating80/100
Number of ratings1
Active installs20
Developer Profile

Food Truck Locator Developer Profile

Romain Rebotier

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Food Truck Locator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/food-truck-locator/css/foodtrucklocator.css/wp-content/plugins/food-truck-locator/css/leaflet_1.9.4.css/wp-content/plugins/food-truck-locator/js/foodtrucklocator.js/wp-content/plugins/food-truck-locator/js/leaflet_1.9.4.js
Script Paths
/wp-content/plugins/food-truck-locator/js/foodtrucklocator.js/wp-content/plugins/food-truck-locator/js/leaflet_1.9.4.js
Version Parameters
food-truck-locator/css/foodtrucklocator.css?ver=food-truck-locator/css/leaflet_1.9.4.css?ver=food-truck-locator/js/foodtrucklocator.js?ver=food-truck-locator/js/leaflet_1.9.4.js?ver=

HTML / DOM Fingerprints

CSS Classes
foodtrucklocatorfoodtrucklocator-listfoodtrucklocator-editfoodtrucklocator-settings
Data Attributes
data-current_pagedata-plugin_url
JS Globals
foodtrucklocator_ajax_objectleaflet
Shortcode Output
[foodtrucklocator]
FAQ

Frequently Asked Questions about Food Truck Locator