
WP Map Route Planner Security & Risk Analysis
wordpress.org/plugins/wp-map-route-plannerHelp you to locate specific and most direct route, such as WooCommerce order delivery routes or your's custom added route, it integrates a Route …
Is WP Map Route Planner Safe to Use in 2026?
Use With Caution
Score 63/100WP Map Route Planner has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "wp-map-route-planner" plugin v1.0.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and appears to have a minimal attack surface in terms of shortcodes, cron events, and REST API routes. The absence of dangerous functions and file operations is also a strength. However, significant concerns arise from the static analysis, particularly the presence of three AJAX handlers, all of which lack authentication checks. This creates a considerable entry point for unauthorized actions. Furthermore, only a small percentage of output is properly escaped, increasing the risk of Cross-Site Scripting (XSS) vulnerabilities when data is displayed. The taint analysis also identified a flow with an unsanitized path, which could lead to path traversal or other file system related vulnerabilities if exploited, though its severity is not specified as critical or high. The vulnerability history reveals a medium-severity Cross-Site Request Forgery (CSRF) vulnerability that is currently unpatched. The recurrence of CSRF in the plugin's history, coupled with the unprotected AJAX endpoints, suggests a pattern of insufficient input validation and authorization checks, potentially leaving users vulnerable to malicious actions performed without their consent. The plugin has strengths in SQL handling but weaknesses in input validation and authentication for its AJAX endpoints, demanding careful attention.
Key Concerns
- Unprotected AJAX handlers present
- Low output escaping percentage
- Unsanitized path flow identified
- Unpatched medium severity CVE
- All AJAX handlers lack auth checks
WP Map Route Planner Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Map Route Planner <= 1.0.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
WP Map Route Planner Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Map Route Planner Attack Surface
AJAX Handlers 3
WordPress Hooks 6
Maintenance & Trust
WP Map Route Planner Maintenance & Trust
Maintenance Signals
Community Trust
WP Map Route Planner Alternatives
CodePeople Post Map for Google Maps
codepeople-post-map
CodePeople Post Map lets you geotag posts and seamlessly integrate your blog with Google Maps for a smooth, location-aware experience.
Nomad World Map
nomad-world-map
Create your own custom travel map. Link locations on the map to blog posts and share your travel plans.
WP-Routes Plugin
wp-routes
Add Cycle Routes, Mountain Bike Trails, Running Tracks, Walking Routes and much more to your posts and pages.
LogMyTrip
logmytrip
Viewing your posts as a route plotted on a Google map is simple with this plugin. Just add the shortcode [logmytripmap] to a page to see the map.
SP Google Maps
sp-google-maps
SP Google Maps is a lightweight plugin for creating google maps with street view for your WordPress Site.
WP Map Route Planner Developer Profile
8 plugins · 78K total installs
How We Detect WP Map Route Planner
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-map-route-planner/css/vsz-route-planner-admin.css/wp-content/plugins/wp-map-route-planner/css/vsz-rp-print.css/wp-content/plugins/wp-map-route-planner/css/bootstrap.min.css/wp-content/plugins/wp-map-route-planner/css/bootstrap-datepicker.min.css/wp-content/plugins/wp-map-route-planner/css/magnific-popup.css/wp-content/plugins/wp-map-route-planner/css/font-awesome.css/wp-content/plugins/wp-map-route-planner/js/vsz-route-planner-admin.js/wp-content/plugins/wp-map-route-planner/js/bootstrap-datepicker.min.js+6 morejs/vsz-route-planner-admin.jsjs/bootstrap-datepicker.min.jsjs/bootstrap.min.jsjs/jquery.magnific-popup.jsjs/oms.min.jsjs/freezeheader.js+2 morevsz-route-planner-admin.js?ver=vsz-rp-print.css?ver=bootstrap.min.css?ver=bootstrap-datepicker.min.css?ver=magnific-popup.css?ver=font-awesome.css?ver=vsz-route-planner-admin.js?ver=bootstrap-datepicker.min.js?ver=bootstrap.min.js?ver=jquery.magnific-popup.js?ver=oms.min.js?ver=freezeheader.js?ver=urchin.js?ver=styledMarker.js?ver=HTML / DOM Fingerprints
vsz-route-plannerdata-toggledata-targetvsz_route_planner_admin_params