
Travel Routes Security & Risk Analysis
wordpress.org/plugins/travel-routesDisplay your travels on customizable maps !
Is Travel Routes Safe to Use in 2026?
Generally Safe
Score 100/100Travel Routes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "travel-routes" v1.1 plugin exhibits a generally good security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the lack of critical or high-severity taint flows and dangerous function calls suggests careful coding practices in these areas. The plugin also demonstrates some awareness of security by including a nonce check and a capability check.
However, there are significant areas of concern. The most prominent issue is the complete lack of prepared statements for all three SQL queries. This makes the plugin highly susceptible to SQL injection vulnerabilities, a critical security flaw. Additionally, a low percentage (22%) of properly escaped output indicates a high risk of cross-site scripting (XSS) vulnerabilities, as unsanitized output can be rendered by the browser in unintended ways.
The plugin's vulnerability history is clean, with no recorded CVEs. This is a positive sign, but it does not negate the risks identified in the static analysis. The absence of past vulnerabilities could be due to the plugin's limited functionality, low adoption, or simply fortunate circumstances. The identified code-level weaknesses, particularly the raw SQL queries and poor output escaping, represent tangible and exploitable risks that require immediate attention.
Key Concerns
- All SQL queries lack prepared statements
- Low percentage of properly escaped output
Travel Routes Security Vulnerabilities
Travel Routes Code Analysis
SQL Query Safety
Output Escaping
Travel Routes Attack Surface
WordPress Hooks 13
Maintenance & Trust
Travel Routes Maintenance & Trust
Maintenance Signals
Community Trust
Travel Routes Alternatives
Nomad World Map
nomad-world-map
Create your own custom travel map. Link locations on the map to blog posts and share your travel plans.
Geolocation
geolocation
Lightweight display the location information of your post in a map (GDPR comliant). Ideal for travelbloggers or anyone who would like to show the loca …
LogMyTrip
logmytrip
Viewing your posts as a route plotted on a Google map is simple with this plugin. Just add the shortcode [logmytripmap] to a page to see the map.
Travel Map
travel-maps
Travel Baidu Map is a Wordpress plugin to help people to create one or more Baidu maps with locations and route into your site.
WP-Ultimate-Map
wp-ultimate-map
Place a map on your wordpress website with custom markers , infowindows and Routes.
Travel Routes Developer Profile
5 plugins · 140 total installs
How We Detect Travel Routes
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/travel-routes/css/jquery-ui-fresh.css/wp-content/plugins/travel-routes/css/admin.css/wp-content/plugins/travel-routes/js/admin.jstravel-routes/css/jquery-ui-fresh.css?ver=travel-routes/css/admin.css?ver=travel-routes/js/admin.js?ver=HTML / DOM Fingerprints
route-optionscolorpickerroute-maproute-locationslocationparentsautocomplete<!-- Is it a better way to define this ? An array('post', 'page') for the post_type attribute doesn't seem to work. --><!-- Soon we'll activate the language support : load_plugin_textdomain( 'travel-routes', false, dirname( plugin_basename( __FILE__ ) ) . '/lang' ); --><!-- USING THE TAXONOMY-METADATA PLUGIN BY http://profiles.wordpress.org/mitchoyoshitaka/ -->route_showroute_colorroute_dashedroute_location_latituderoute_location_longituderoute_location_place+2 moregoogle