
WP-Routes Plugin Security & Risk Analysis
wordpress.org/plugins/wp-routesAdd Cycle Routes, Mountain Bike Trails, Running Tracks, Walking Routes and much more to your posts and pages.
Is WP-Routes Plugin Safe to Use in 2026?
Generally Safe
Score 85/100WP-Routes Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-routes v0.4 plugin exhibits a mixed security posture. On the positive side, the plugin demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having no recorded vulnerabilities or CVEs. The attack surface appears to be minimal, with no identified AJAX handlers, REST API routes, shortcodes, or cron events. However, significant concerns arise from the code analysis. A very low percentage of output escaping (4%) is a critical weakness, potentially exposing the application to cross-site scripting (XSS) vulnerabilities if user-supplied data is ever processed or displayed without proper sanitization. Furthermore, all analyzed taint flows (4 out of 4) have unsanitized paths, which could lead to various injection vulnerabilities if these paths involve user-controlled input. The absence of nonce checks and capability checks, while currently not directly exploitable due to a zero attack surface, represents a missed opportunity for robust security in case the plugin evolves to include user-facing entry points. In conclusion, while the plugin's current lack of known vulnerabilities and its use of prepared statements are strengths, the severe lack of output escaping and the high number of unsanitized taint flows are significant risks that require immediate attention.
Key Concerns
- Low output escaping percentage
- Taint flows with unsanitized paths
- No nonce checks
- No capability checks
WP-Routes Plugin Security Vulnerabilities
WP-Routes Plugin Code Analysis
Output Escaping
Data Flow Analysis
WP-Routes Plugin Attack Surface
WordPress Hooks 12
Maintenance & Trust
WP-Routes Plugin Maintenance & Trust
Maintenance Signals
Community Trust
WP-Routes Plugin Alternatives
Google Maps Photo Gallery
google-maps-photo-gallery
The shortcode for gallery on Google Maps with geotagged photos.
Gellum Delivery Calculator for WooCommerce
gellum-delivery-calculator
Calculates shipping costs for WooCommerce based on GPS distance with GeoJSON limited areas. Shortcode [gellumdcw_map]
Google Maps Hyperlink
google-maps-hyperlink
Converts a shortcode with the format [gmaplink name="description" gps="xºxx.xxxN,xºxx.xxxW"] to a google maps hyperlink
Posts on a map
posts-on-a-map
Add a custom field for GPS coordinates in the post editor and show a map under under the content of the post.
Simply Strava
simply-strava
A simple Strava widget for Wordpress
WP-Routes Plugin Developer Profile
1 plugin · 100 total installs
How We Detect WP-Routes Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
[gpsies url width height]