
Run Log Security & Risk Analysis
wordpress.org/plugins/run-logAdd running diary capabilities - log your sport activities, track and display: distance, duration, gear (e.g. shoes), elevation gain, calories, etc.
Is Run Log Safe to Use in 2026?
Generally Safe
Score 99/100Run Log has a strong security track record. Known vulnerabilities have been patched promptly.
The 'run-log' plugin v1.7.12 exhibits a generally positive security posture, largely due to its adherence to secure coding practices like using prepared statements for all SQL queries and implementing nonce and capability checks. The limited attack surface, with only one shortcode and no AJAX handlers or REST API routes exposed without authentication, further contributes to its security. The complete absence of critical or high severity taint flows and dangerous functions is also commendable, indicating a low risk of direct code execution vulnerabilities.
However, the static analysis reveals a notable concern regarding output escaping, with only 60% of outputs being properly escaped. This leaves a significant portion of the plugin's output potentially vulnerable to Cross-Site Scripting (XSS) attacks, especially if user-supplied data is not adequately sanitized before being displayed. The plugin's vulnerability history, while currently showing no unpatched CVEs, does include a past medium severity Cross-Site Request Forgery (CSRF) vulnerability. This indicates that while the developers are responsive to patching, the potential for such vulnerabilities to exist or re-emerge should not be entirely dismissed.
In conclusion, 'run-log' v1.7.12 demonstrates a solid foundation in secure development with its robust SQL handling and authentication checks. The primary weakness lies in the incomplete output escaping, which presents a tangible XSS risk. The past CSRF vulnerability also warrants attention. Addressing the output escaping issues should be the highest priority to further strengthen the plugin's security.
Key Concerns
- Incomplete output escaping
- Past medium severity CSRF vulnerability
Run Log Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Run Log <= 1.7.10 - Cross-Site Request Forgery to Settings Update
Run Log Code Analysis
SQL Query Safety
Output Escaping
Run Log Attack Surface
Shortcodes 1
WordPress Hooks 16
Maintenance & Trust
Run Log Maintenance & Trust
Maintenance Signals
Community Trust
Run Log Alternatives
Custom Strava Integration
custom-strava-integration
This plugin provides an easy way to add your strava activities to your posts without leaving your site.
Simply Strava
simply-strava
A simple Strava widget for Wordpress
SportsPress – Sports Club & League Manager
sportspress
SportsPress is an extendable all-in-one sports data plugin that helps sports clubs set up and manage a league or club site quickly and easily.
WPCargo Track & Trace
wpcargo
WPCargo is a track & trace system for courier, courier script, parcel, balikbayan system, shipment and transportation management system, ideal sol …
SportsPress for Football (Soccer)
sportspress-for-soccer
SportsPress for Football is an extension for SportsPress, an all-in-one sports data plugin that helps sports clubs set up a football website.
Run Log Developer Profile
7 plugins · 198K total installs
How We Detect Run Log
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/run-log/css/run-log.css/wp-content/plugins/run-log/js/run-log.js/wp-content/plugins/run-log/js/run-log.jsrun-log/css/run-log.css?ver=run-log/js/run-log.js?ver=HTML / DOM Fingerprints
oirl-run-log-entryoirl-run-log-titleoirl-run-log-dateoirl-run-log-distanceoirl-run-log-paceoirl-run-log-gearoirl-run-log-goaloirl-run-log-excerptdata-oirl-optionsrunLogOptions