
Route ‑ Shipping Protection Security & Risk Analysis
wordpress.org/plugins/routeappOne-Click Shipping Protection
Is Route ‑ Shipping Protection Safe to Use in 2026?
Generally Safe
Score 100/100Route ‑ Shipping Protection has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'routeapp' plugin v2.3.0 exhibits a concerning security posture primarily due to a significant number of unprotected entry points. Out of 17 identified entry points, 16 lack proper authentication or capability checks. This includes all 12 AJAX handlers and all 4 REST API routes. While the code analysis shows no dangerous functions, no raw SQL queries, and a low number of external HTTP requests, the sheer volume of unprotected endpoints presents a substantial attack surface. Taint analysis revealed no critical or high-severity vulnerabilities, and the plugin has no known CVEs, which are positive indicators. However, the lack of output escaping on a majority of outputs (76%) combined with the unprotected entry points creates a significant risk of cross-site scripting (XSS) or other injection attacks if user-supplied data is processed without proper sanitization and output encoding.
The plugin's vulnerability history is clean, which is commendable. This could indicate good development practices regarding security or simply a lack of prior discovery. However, the static analysis results strongly suggest that good practices are not being consistently applied, particularly concerning input validation and access control. The strengths lie in the absence of dangerous functions, prepared SQL statements, and known vulnerabilities. The major weakness is the extensive unprotected attack surface and insufficient output escaping, which are critical security oversights.
Key Concerns
- 12 AJAX handlers without auth checks
- 4 REST API routes without permission callbacks
- 17 total outputs, 24% properly escaped
- 2 Nonce checks, 16 unprotected entry points
Route ‑ Shipping Protection Security Vulnerabilities
Route ‑ Shipping Protection Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Route ‑ Shipping Protection Attack Surface
AJAX Handlers 12
REST API Routes 4
Shortcodes 1
WordPress Hooks 64
Maintenance & Trust
Route ‑ Shipping Protection Maintenance & Trust
Maintenance Signals
Community Trust
Route ‑ Shipping Protection Alternatives
Seel Worry-Free Purchase
seel-worry-free-purchase
Automate returns/exchanges and protect orders with real-time tracking and comprehensive coverage.
Extend Protection For WooCommerce
helloextend-protection
Extend helps merchants generate revenue and protect customers from damage and loss through modern product and shipping protection solutions.
WPSQR Media Protector – Prevent Used Image Deletion
wpsqr-media-protector
Protect your WordPress media library by preventing the deletion of images that are actively used across your website.
Disable Comments – Remove Comments & Stop Spam [Multi-Site Support]
disable-comments
Allows administrators to globally disable comments on their site. Comments can be disabled according to post type. Multisite friendly.
Antispam Bee
antispam-bee
Sophisticated antispam plugin for effective daily comment and trackback spam-fighting. Built with data protection and privacy in mind.
Route ‑ Shipping Protection Developer Profile
1 plugin · 600 total installs
How We Detect Route ‑ Shipping Protection
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/routeapp/admin/css/routeapp-admin.css/wp-content/plugins/routeapp/admin/js/routeapp-admin.js/wp-content/plugins/routeapp/includes/js/routeapp-public.js/wp-content/plugins/routeapp/admin/js/routeapp-admin.js/wp-content/plugins/routeapp/includes/js/routeapp-public.jsrouteapp-admin.css?ver=routeapp-admin.js?ver=routeapp-public.js?ver=HTML / DOM Fingerprints
routeapp-protected-bannerdata-route-widget-containerrouteapp_public_paramsRouteApp[routeapp_protected_banner]