
Show Fit File Security & Risk Analysis
wordpress.org/plugins/show-fit-fileA plugin to display fit, gpx and tcx files.
Is Show Fit File Safe to Use in 2026?
Generally Safe
Score 85/100Show Fit File has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "show-fit-file" plugin v1.2.3 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, file operations, external HTTP requests, and the complete use of prepared statements for SQL queries are strong indicators of secure coding practices. Furthermore, the lack of any recorded vulnerabilities, including critical and high severity ones, suggests a history of responsible development and maintenance. The plugin's attack surface is minimal, with only one shortcode, and importantly, no AJAX handlers or REST API routes appear to be unprotected. This indicates a careful approach to integrating with WordPress, minimizing potential entry points for attackers.
Key Concerns
- One shortcode, no specified auth check
- Only 67% of outputs properly escaped
- No nonce checks present
- No capability checks present
Show Fit File Security Vulnerabilities
Show Fit File Code Analysis
Output Escaping
Show Fit File Attack Surface
Shortcodes 1
WordPress Hooks 7
Maintenance & Trust
Show Fit File Maintenance & Trust
Maintenance Signals
Community Trust
Show Fit File Alternatives
Garmin Connect
garmin-connect
Provides a widget for displaying latest activities from Garmin Connect on your site
Gpx2Graphics
gpx2graphics
Create a Google Map, Elevation image or Speed image from your (Garmin) GpX files.
Tracking Code Manager
tracking-code-manager
A plugin to manage ALL of your tracking code and conversion pixels. Compatible with Facebook Ads, Google Adwords, WooCommerce, Easy Digital Downloads, …
Cost of Goods: Product Cost & Profit Calculator for WooCommerce
cost-of-goods-for-woocommerce
Unlock detailed insights into products profitability, calculate COGS & profit margins, and get a better financial analytics insights with our Cost …
OSM – OpenStreetMap
osm
Customize maps in your post, pages and widgets. GPX, KML and more. The easy way to map!
Show Fit File Developer Profile
1 plugin · 100 total installs
How We Detect Show Fit File
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/show-fit-file/leaflet.js/wp-content/plugins/show-fit-file/leaflet.css/wp-content/plugins/show-fit-file/style.css/wp-content/plugins/show-fit-file/images/trend-up.svg/wp-content/plugins/show-fit-file/images/trend-down.svg/wp-content/plugins/show-fit-file/leaflet.js/wp-content/plugins/show-fit-file/build/index.jsshow-fit-file/leaflet.js?ver=show-fit-file/leaflet.css?ver=show-fit-file/style.css?ver=HTML / DOM Fingerprints
sff_dataCellsff_dataTitlesff_dataItemsff_trendsff_dataTablesff_altitudeGraphsff_routeMapCopyright (c), Stuart Tevendale, 2018 - 2023Code for BlockThis is separate to Shortcode functions so that I can add extra functionality
to the block without breaking the Shortcode version
The alternative is splitting the plugin into 2 separate pluginsAdd code for Block+1 moreid="mapid-class="sff_routeMap"class="sff_altitudeGraph"id="altitude"class="sff_dataTable"class="sff_dataCell"+3 moreL.mapL.TileLayerL.polylineL.markerL.circleMarkergreenIcon+14 more<table class="sff_dataTable"<div id="mapid-<canvas id="altitude">