
Lf Hiker Security & Risk Analysis
wordpress.org/plugins/lf-hikerLf Hiker is a plugin for quickly display your gpx tracks with their profile elevation on an interactive map.
Is Lf Hiker Safe to Use in 2026?
Generally Safe
Score 85/100Lf Hiker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lf-hiker" plugin v1.13.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, exclusively using prepared statements for SQL queries, and showing no known historical vulnerabilities. This suggests a conscious effort by the developers to maintain a secure codebase. However, there are significant concerns stemming from the static analysis. The plugin exposes two AJAX handlers without any authentication checks, creating a direct attack vector that could be exploited by unauthenticated users. Furthermore, a substantial portion (47%) of its output is not properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities when user-controlled data is displayed.
The lack of taint analysis data is neither a positive nor a negative indicator in itself, as it might simply mean no such flows were detected or the analysis tooling wasn't configured to find them. The vulnerability history being completely clean is a strong positive signal, suggesting a history of responsible development. However, the presence of unprotected entry points and unescaped output in the current version are significant weaknesses that must be addressed. The current version has clear vulnerabilities that attackers could exploit, despite the absence of historical issues.
Key Concerns
- AJAX handlers without authentication
- Significant unescaped output
- Bundled library (TinyMCE) may have vulnerabilities
Lf Hiker Security Vulnerabilities
Lf Hiker Code Analysis
Bundled Libraries
Output Escaping
Lf Hiker Attack Surface
AJAX Handlers 2
Shortcodes 3
WordPress Hooks 22
Maintenance & Trust
Lf Hiker Maintenance & Trust
Maintenance Signals
Community Trust
Lf Hiker Alternatives
Waymark
waymark
Waymark adds powerful mapping features to WordPress that are easy to use. Create beautiful, interactive Maps customised to suit your needs.
GPX Viewer
gpx-viewer
Display GPX tracks with their elevation profile on OSM maps, edit them interactively
Tracking Code Manager
tracking-code-manager
A plugin to manage ALL of your tracking code and conversion pixels. Compatible with Facebook Ads, Google Adwords, WooCommerce, Easy Digital Downloads, …
OSM – OpenStreetMap
osm
Customize maps in your post, pages and widgets. GPX, KML and more. The easy way to map!
WP GPX Maps
wp-gpx-maps
Draws a GPX track with altitude graph. You can also display your nextgen gallery images in the map.
Lf Hiker Developer Profile
1 plugin · 200 total installs
How We Detect Lf Hiker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lf-hiker/lib/leaflet/1.3.1/leaflet.css/wp-content/plugins/lf-hiker/lib/leaflet/1.3.1/leaflet.js/wp-content/plugins/lf-hiker/lib/awesome-marker/leaflet.awesome-markers.css/wp-content/plugins/lf-hiker/lib/awesome-marker/leaflet.awesome-markers.js/wp-content/plugins/lf-hiker/lib/leaflet-gpx.js/wp-content/plugins/lf-hiker/css/lfh-style.css/wp-content/plugins/lf-hiker/js/lfh-plugin.js/wp-content/plugins/lf-hiker/dist/lfh-style-min.1.13.0.css+1 more/wp-content/plugins/lf-hiker/lib/leaflet-gpx.js/wp-content/plugins/lf-hiker/js/lfh-plugin.js/wp-content/plugins/lf-hiker/dist/lfh-front-min.1.13.0.jslfh-style-min.1.13.0.csslfh-front-min.1.13.0.jsHTML / DOM Fingerprints
lfh-map-container<!-- @todo (can do this with js) -->data-lfh-map-idLf_Hiker_PluginLfh_Controller_FrontLf_Hiker_Plugin::VERSIONLf_Hiker_Plugin::LEAFLET_VERSION[lfh-map][lfh-marker][lfh-gpx]