
b-Locator Security & Risk Analysis
wordpress.org/plugins/b-locatorb-Locator is a plugin that can generate custom locator ( e.g. Store Locator, Distributor Locator, etc. )
Is b-Locator Safe to Use in 2026?
Generally Safe
Score 85/100b-Locator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "b-locator" plugin v1.0.1 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not using dangerous functions, handling all SQL queries with prepared statements, and conducting nonce checks. The absence of file operations and external HTTP requests further reduces potential attack vectors. However, a significant concern arises from the plugin's attack surface. It exposes two AJAX handlers, both of which lack proper authentication checks. This creates a clear vulnerability where unauthenticated users could potentially interact with these handlers, leading to unintended consequences if the functionality within them is sensitive.
The taint analysis shows no identified flows, which is a positive indicator, suggesting that data flowing through the analyzed code is not being mishandled in critical ways. Similarly, the plugin's vulnerability history is clean, with no known CVEs. This suggests a lack of previously discovered critical flaws, which is encouraging for its current state. However, the presence of unprotected AJAX endpoints is a proactive risk that needs immediate attention, even in the absence of historical vulnerabilities.
In conclusion, while "b-locator" v1.0.1 shows strengths in its secure handling of database operations and its clean vulnerability record, the two unprotected AJAX handlers represent a substantial security weakness. The plugin has a small attack surface, but a significant portion of it is unprotected. Addressing these unprotected entry points is paramount to improving its overall security. The lack of historical vulnerabilities is a good sign, but it does not negate the immediate risk presented by the unprotected AJAX handlers.
Key Concerns
- AJAX handlers without auth checks
- AJAX handlers without auth checks
- Output escaping below 100%
b-Locator Security Vulnerabilities
b-Locator Release Timeline
b-Locator Code Analysis
Output Escaping
b-Locator Attack Surface
AJAX Handlers 2
WordPress Hooks 13
Maintenance & Trust
b-Locator Maintenance & Trust
Maintenance Signals
Community Trust
b-Locator Alternatives
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
WP Store Locator
wp-store-locator
An easy to use location management system that enables users to search for nearby physical stores.
MapPress Maps for WordPress
mappress-google-maps-for-wordpress
MapPress is the easiest way to add unlimited interactive Google and Leaflet maps to WordPress.
Store Locator WordPress
agile-store-locator
Agile Store Locator is a premium store finder plugin designed to offer you immediate access to all the best stores in your local area.
Maps Plugin using Google Maps for WordPress – WP Google Map
gmap-embed
Google Map plugin for WordPress is very Simple, light-weight and Easy to use Google Custom Map with markers in Posts, Pages, Sidebar as shortcode.
b-Locator Developer Profile
1 plugin · 0 total installs
How We Detect b-Locator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/b-locator/frontend/css/frontend.css/wp-content/plugins/b-locator/frontend/js/frontend.js/wp-content/plugins/b-locator/backend/css/backend.css/wp-content/plugins/b-locator/backend/js/backend.js//maps.googleapis.com/maps/api/jsHTML / DOM Fingerprints
b-locator-map-container<!-- START: b-locator --><!-- END: b-locator -->data-location-iddata-location-namedata-location-addressdata-location-citydata-location-statedata-location-zip+6 moreajaxurlcenter_longcenter_latzoom_levelgoogle_map_themegoogle_map_marker+5 more/wp-json/b-locator/v1/locations[b-locator][b-locator-map]