
run-route Security & Risk Analysis
wordpress.org/plugins/run-routeAdds a shortcode to display links to routes in Endomondo and RunKeeper
Is run-route Safe to Use in 2026?
Generally Safe
Score 85/100run-route has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'run-route' v1.1 plugin exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, reliance on prepared statements for all SQL queries, and proper output escaping are excellent security practices. The fact that there are no unpatched CVEs, no recorded vulnerabilities, and no critical or high-severity taint flows further reinforces this positive assessment. The plugin's attack surface is minimal, with only one shortcode, and importantly, no unprotected entry points were identified in the static analysis, indicating that known entry points have some form of protection.
However, a key concern arises from the complete absence of nonce checks and capability checks. While the static analysis reported zero unprotected entry points, this could be due to the specific way the shortcode is implemented or how other potential entry points are handled internally. The lack of explicit nonce and capability checks, especially for any logic that might be triggered by the shortcode, leaves room for potential CSRF (Cross-Site Request Forgery) attacks or privilege escalation if user context isn't rigorously verified. Overall, the plugin demonstrates a good foundation in secure coding, but the reliance on implicit security for its entry points, particularly the shortcode, warrants attention.
Key Concerns
- Missing nonce checks
- Missing capability checks
run-route Security Vulnerabilities
run-route Code Analysis
Output Escaping
run-route Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
run-route Maintenance & Trust
Maintenance Signals
Community Trust
run-route Alternatives
WP Shortcodes Plugin — Shortcodes Ultimate
shortcodes-ultimate
A comprehensive collection of visual components for your site
MW WP Form
mw-wp-form
MW WP Form is shortcode base contact form plugin. This plugin have many features. For example you can use many validation rules, inquiry data saving, …
Shortcoder — Create Shortcodes for Anything
shortcoder
Create custom "Shortcodes" easily for HTML, JavaScript, CSS code snippets and use the shortcodes within posts, pages & widgets
Display Posts – Easy lists, grids, navigation, and more
display-posts-shortcode
Add a listing of content on your website using a simple shortcode. Filter the results by category, author, and more.
WP Show Posts
wp-show-posts
Add posts to your website from any post type using a simple shortcode.
run-route Developer Profile
3 plugins · 30 total installs
How We Detect run-route
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/run-route/run-route.cssrun-route.css?ver=HTML / DOM Fingerprints
run-routeendomondorunkeeperrun-route-image<div class='run-route'><span class='endomondo'><a href='http://endomondo.com/routes/<img class='run-route-image' src='' alt='Show route in Endomondo' title='Show route in Endomondo' width='50' height='54' /></a></span>