Lift & Trail Status Security & Risk Analysis

wordpress.org/plugins/lift-trail-status

Display the status of lifts and trails for your ski resort or adventure park on your website. Great for mountain bike, water, ropes & adventure parks.

0 active installs v1.4.7 PHP 8.0+ WP 4.7+ Updated Apr 9, 2025
bikinghikingliftsskiingtrails
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Lift & Trail Status Safe to Use in 2026?

Generally Safe

Score 100/100

Lift & Trail Status has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 12mo ago
Risk Assessment

The "lift-trail-status" plugin v1.4.7 exhibits a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having no recorded historical vulnerabilities. This suggests a developer who is aware of common security pitfalls. However, there are significant concerns related to its attack surface and input sanitization.

The primary risk stems from the presence of one AJAX handler that lacks authentication checks. This creates a direct entry point for unauthenticated users to potentially interact with plugin functionality, which could lead to unintended consequences if not properly secured within the handler itself. Furthermore, the taint analysis revealed three flows with unsanitized paths, although these did not reach a critical or high severity according to the analysis. This, coupled with only 40% of output being properly escaped, indicates potential vulnerabilities to cross-site scripting (XSS) or information disclosure if the unsanitized inputs are used in sensitive contexts or displayed without adequate escaping.

The absence of any recorded historical vulnerabilities is a strong positive indicator. It suggests the plugin has either not been a target or has been developed with a degree of security consciousness. However, the findings from the static analysis, particularly the unprotected AJAX endpoint and the taint analysis indicating unsanitized paths, highlight areas where the plugin's security could be significantly strengthened. The plugin's strengths lie in its lack of historical issues and safe SQL practices, but its weaknesses are evident in its attack surface management and input validation.

Key Concerns

  • Unprotected AJAX handler
  • Unsanitized paths in taint analysis
  • Low percentage of properly escaped output
  • No nonce checks on AJAX
  • No capability checks
Vulnerabilities
None known

Lift & Trail Status Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Lift & Trail Status Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
71
48 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

40% escaped119 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

3 flows3 with unsanitized paths
settings_page (includes\class-mwps-admin.php:72)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Lift & Trail Status Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_mwps_validate_data_feed_urlincludes\class-mwps-admin.php:29
WordPress Hooks 7
actionplugins_loadedincludes\class-medic52-wpstatus.php:260
actioninitincludes\class-medic52-wpstatus.php:262
actionwp_enqueue_scriptsincludes\class-medic52-wpstatus.php:264
actionwp_headincludes\class-medic52-wpstatus.php:267
actionadmin_menuincludes\class-mwps-admin.php:20
actionadmin_enqueue_scriptsincludes\class-mwps-admin.php:23
actionadmin_noticesincludes\class-mwps-install.php:19
Maintenance & Trust

Lift & Trail Status Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 9, 2025
PHP min version8.0
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Lift & Trail Status Developer Profile

Medic52

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Lift & Trail Status

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lift-trail-status/css/lift-trail-status.css/wp-content/plugins/lift-trail-status/js/lift-trail-status.js
Script Paths
/wp-content/plugins/lift-trail-status/js/lift-trail-status.js
Version Parameters
lift-trail-status/css/lift-trail-status.css?ver=lift-trail-status/js/lift-trail-status.js?ver=

HTML / DOM Fingerprints

CSS Classes
medic52-lift-trail-status-wrappermedic52-lift-trail-status-titlemedic52-lift-trail-status-itemmedic52-lift-trail-status-condition
Data Attributes
data-plugin-version
JS Globals
mwps_ajax_object
Shortcode Output
[lift_trail_status]
FAQ

Frequently Asked Questions about Lift & Trail Status