
Lift & Trail Status Security & Risk Analysis
wordpress.org/plugins/lift-trail-statusDisplay the status of lifts and trails for your ski resort or adventure park on your website. Great for mountain bike, water, ropes & adventure parks.
Is Lift & Trail Status Safe to Use in 2026?
Generally Safe
Score 100/100Lift & Trail Status has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "lift-trail-status" plugin v1.4.7 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having no recorded historical vulnerabilities. This suggests a developer who is aware of common security pitfalls. However, there are significant concerns related to its attack surface and input sanitization.
The primary risk stems from the presence of one AJAX handler that lacks authentication checks. This creates a direct entry point for unauthenticated users to potentially interact with plugin functionality, which could lead to unintended consequences if not properly secured within the handler itself. Furthermore, the taint analysis revealed three flows with unsanitized paths, although these did not reach a critical or high severity according to the analysis. This, coupled with only 40% of output being properly escaped, indicates potential vulnerabilities to cross-site scripting (XSS) or information disclosure if the unsanitized inputs are used in sensitive contexts or displayed without adequate escaping.
The absence of any recorded historical vulnerabilities is a strong positive indicator. It suggests the plugin has either not been a target or has been developed with a degree of security consciousness. However, the findings from the static analysis, particularly the unprotected AJAX endpoint and the taint analysis indicating unsanitized paths, highlight areas where the plugin's security could be significantly strengthened. The plugin's strengths lie in its lack of historical issues and safe SQL practices, but its weaknesses are evident in its attack surface management and input validation.
Key Concerns
- Unprotected AJAX handler
- Unsanitized paths in taint analysis
- Low percentage of properly escaped output
- No nonce checks on AJAX
- No capability checks
Lift & Trail Status Security Vulnerabilities
Lift & Trail Status Code Analysis
Output Escaping
Data Flow Analysis
Lift & Trail Status Attack Surface
AJAX Handlers 1
WordPress Hooks 7
Maintenance & Trust
Lift & Trail Status Maintenance & Trust
Maintenance Signals
Community Trust
Lift & Trail Status Alternatives
Trail Status
trail-status
Display the status of trails on your website.
Outdooractive Embed
outdooractive-embed
Embed any kind of content from outdooractive.com into your WordPress site.
Trail Monitor
vstm-trail-monitor
Display the status of trails on your website.
Strava Ride Details
strava-ride-details
This plugin allows you to display Strava ride details from a specific ride in your posts and pages using a shortcode.
Custom Strava Integration
custom-strava-integration
This plugin provides an easy way to add your strava activities to your posts without leaving your site.
Lift & Trail Status Developer Profile
1 plugin · 0 total installs
How We Detect Lift & Trail Status
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lift-trail-status/css/lift-trail-status.css/wp-content/plugins/lift-trail-status/js/lift-trail-status.js/wp-content/plugins/lift-trail-status/js/lift-trail-status.jslift-trail-status/css/lift-trail-status.css?ver=lift-trail-status/js/lift-trail-status.js?ver=HTML / DOM Fingerprints
medic52-lift-trail-status-wrappermedic52-lift-trail-status-titlemedic52-lift-trail-status-itemmedic52-lift-trail-status-conditiondata-plugin-versionmwps_ajax_object[lift_trail_status]