Tuskcode Map Pro for Bing Maps Security & Risk Analysis

wordpress.org/plugins/api-bing-map-2018

Designed to create accesible maps from bing, with multiple options of pins, width, height, custom pins, and address.

800 active installs v5.0.5 PHP 5.2.4+ WP 5.3+ Updated Feb 18, 2026
api-bing-mapbingbing-mapmaps
100
A · Safe
CVEs total1
Unpatched0
Last CVEOct 3, 2023
Safety Verdict

Is Tuskcode Map Pro for Bing Maps Safe to Use in 2026?

Generally Safe

Score 100/100

Tuskcode Map Pro for Bing Maps has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Oct 3, 2023Updated 1mo ago
Risk Assessment

The api-bing-map-2018 plugin v5.0.5 presents a mixed security posture. While it shows some good practices like a high percentage of prepared statements for SQL queries and a good rate of output escaping, significant concerns arise from its attack surface. All seven identified AJAX handlers lack authentication checks, exposing them to potential unauthorized execution. Furthermore, the taint analysis revealed seven high-severity flows with unsanitized paths, indicating a strong likelihood of critical vulnerabilities like Cross-Site Scripting (XSS) or Remote Code Execution (RCE) if these flows are exploitable. The plugin's vulnerability history shows one medium-severity CVE, suggesting a past struggle with security, and its pattern of common vulnerabilities including CSRF reinforces the need for robust input validation and authorization. The lack of authentication on AJAX endpoints is a primary area of concern, which, combined with the high-severity taint flows, elevates the overall risk.

Key Concerns

  • Unprotected AJAX handlers
  • High severity unsanitized taint flows
  • Medium severity CVE history
  • Low capability checks
Vulnerabilities
1

Tuskcode Map Pro for Bing Maps Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-45052medium · 4.3Cross-Site Request Forgery (CSRF)

WP Bing Map Pro <= 4.1.4 - Cross-Site Request Forgery via AJAX actions

Oct 3, 2023 Patched in 5.0 (112d)
Code Analysis
Analyzed Mar 16, 2026

Tuskcode Map Pro for Bing Maps Code Analysis

Dangerous Functions
0
Raw SQL Queries
21
87 prepared
Unescaped Output
87
291 escaped
Nonce Checks
8
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

81% prepared108 total queries

Output Escaping

77% escaped378 total outputs
Data Flows
8 unsanitized

Data Flow Analysis

8 flows8 with unsanitized paths
bmp_general_settings (includes\BingMapPro_LifeCycle.php:596)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
7 unprotected

Tuskcode Map Pro for Bing Maps Attack Surface

Entry Points7
Unprotected7

AJAX Handlers 7

authwp_ajax_bmp_general_settingsincludes\BingMapPro_Plugin.php:278
authwp_ajax_bmp_map_actionsincludes\BingMapPro_Plugin.php:280
authwp_ajax_bmp_save_mapincludes\BingMapPro_Plugin.php:283
authwp_ajax_bmp_new_pinincludes\BingMapPro_Plugin.php:287
authwp_ajax_bmp_pin_actionsincludes\BingMapPro_Plugin.php:289
authwp_ajax_bmp_ajax_permissionsincludes\BingMapPro_Plugin.php:291
authwp_ajax_bmp_shape_actionsincludes\BingMapPro_Plugin.php:293
WordPress Hooks 10
actionplugins_loadedincludes\BingMapPro_Plugin.php:270
actionadmin_menuincludes\BingMapPro_Plugin.php:275
actionadmin_enqueue_scriptsincludes\BingMapPro_Plugin.php:285
actioninitincludes\BingMapPro_Plugin.php:296
actionadmin_footerincludes\BingMapPro_Plugin.php:299
actionwp_footerincludes\BingMapPro_Plugin.php:302
filteruser_can_richeditincludes\BingMapPro_Plugin.php:339
filteruser_can_richeditincludes\BingMapPro_Plugin.php:351
actionwp_footerincludes\BingMapPro_ShortCodeScriptLoader.php:15
actionplugins_loadedwp-bing-map-pro.php:24
Maintenance & Trust

Tuskcode Map Pro for Bing Maps Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 18, 2026
PHP min version5.2.4
Downloads35K

Community Trust

Rating96/100
Number of ratings19
Active installs800
Developer Profile

Tuskcode Map Pro for Bing Maps Developer Profile

dan009

5 plugins · 2K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
112 days
View full developer profile
Detection Fingerprints

How We Detect Tuskcode Map Pro for Bing Maps

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/api-bing-map-2018/css/bingmap_admin.css/wp-content/plugins/api-bing-map-2018/css/bingmap_public.css/wp-content/plugins/api-bing-map-2018/js/bingmap_admin.js/wp-content/plugins/api-bing-map-2018/js/bingmap_public.js

HTML / DOM Fingerprints

CSS Classes
bmp_map_container
Data Attributes
data-bmp-map-iddata-bmp-pin-id
JS Globals
bmp_optionsbmp_admin_settingsbingmap_public_init
Shortcode Output
[bing-map-pro
FAQ

Frequently Asked Questions about Tuskcode Map Pro for Bing Maps