
Ship Log Security & Risk Analysis
wordpress.org/plugins/ship-logCreate and store profiles on all your ships/boats along with logs of every outing and adventure
Is Ship Log Safe to Use in 2026?
Generally Safe
Score 85/100Ship Log has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "ship-log" plugin v1.3.4 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events significantly limits its attack surface. Furthermore, the code analysis indicates a complete absence of dangerous functions and file operations. All SQL queries are properly prepared, and there are no external HTTP requests, which are all excellent security practices.
However, a notable concern is the significant percentage of improperly escaped output (41%). While the total number of output operations is high (133), a substantial portion of these do not appear to have proper escaping applied. This presents a risk of Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is directly outputted without sanitization. The lack of any identified nonce or capability checks, while not directly indicative of a vulnerability in itself due to the limited attack surface, suggests that if new entry points were to be introduced in the future, they might lack fundamental security controls.
The plugin also has no recorded vulnerability history, which is a positive indicator of its past security. Combined with the current lack of critical or high severity issues in the static analysis, this suggests a generally well-maintained and secure codebase. However, the unescaped output remains the primary area for improvement to further harden the plugin.
Key Concerns
- Unescaped output detected (41%)
- No nonce checks implemented
- No capability checks implemented
Ship Log Security Vulnerabilities
Ship Log Release Timeline
Ship Log Code Analysis
Output Escaping
Ship Log Attack Surface
Maintenance & Trust
Ship Log Maintenance & Trust
Maintenance Signals
Community Trust
Ship Log Alternatives
Posts 2 Posts
posts-to-posts
Efficient many-to-many connections between posts, pages, custom post types, users.
WPCargo Track & Trace
wpcargo
WPCargo is a track & trace system for courier, courier script, parcel, balikbayan system, shipment and transportation management system, ideal sol …
MembershipWorks Login Connector
memberfindme-login-connector
Allows members to sign in to MembershipWorks and as a WordPress user on your site.
Wild Apricot Login
wild-apricot-login
Provides single sign-on service for Wild Apricot members to provide access to restricted Wild Apricot content.
Advanced Custom Fields – Widget Relationship Field add-on
advanced-custom-fields-widget-relationship-field-add-on
This plugin is an add-on for Advanced Custom Fields. It allows you to use an ACF "relationship" field to choose widgets at a page level.
Ship Log Developer Profile
11 plugins · 11K total installs
How We Detect Ship Log
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ships-log/lib/bl/js/jquery-ui/jquery-ui.min.js/wp-content/plugins/ships-log/lib/bl/css/bl.css/wp-content/plugins/ships-log/css/ships-log.css/wp-content/plugins/ships-log/lib/bl/js/jquery-ui/jquery-ui.min.jsships-log/css/ships-log.css?ver=ships-log/lib/bl/css/bl.css?ver=ships-log/lib/bl/js/jquery-ui/jquery-ui.min.js?ver=HTML / DOM Fingerprints
ships-logSHIPS MENUTRIP PURPOSEENTRY DATEDEPARTURE TIME+16 moreid="ShipId"name="log[ShipId]"id="LogTripPurpose"name="log[TripPurpose]"id="LogEntryDate"name="log[EntryDate]"+34 more