BG Map Security & Risk Analysis

wordpress.org/plugins/bg-map

Bulgaria Map plugin for creating an interactive map of Bulgaria.

0 active installs v1.1.1 PHP 7.0+ WP 1.1.1+ Updated Nov 15, 2022
bg-mapinteractive-map-of-bulgariamap-bulgariamap-bulgarien
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is BG Map Safe to Use in 2026?

Generally Safe

Score 85/100

BG Map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "bg-map" plugin v1.1.1 appears to have a strong security posture. The code analysis reveals an absence of dangerous functions, all SQL queries utilize prepared statements, and all output is properly escaped. Furthermore, there are no indications of file operations, external HTTP requests, or any known vulnerability history. This suggests a conscientious development approach with a focus on core security practices.

However, there are a few areas that warrant attention. The complete lack of nonce checks and capability checks, coupled with the presence of a shortcode, indicates potential for vulnerabilities if user-supplied data is not handled with extreme care within the shortcode's execution. While taint analysis shows no issues, this is based on zero flows being analyzed, which itself is a limitation. The absence of known CVEs is positive but does not guarantee future security if the identified gaps are not addressed.

In conclusion, while the plugin demonstrates good practices in areas like SQL and output escaping, the absence of authentication checks on its entry points (shortcodes) presents a theoretical risk. The zero taint flow analysis is not a definitive positive, but rather an area where more rigorous analysis would be beneficial. The plugin's current state suggests low immediate risk but highlights areas for improvement to enhance its overall security resilience.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • Shortcode exists without auth checks
  • Taint analysis not performed (zero flows)
Vulnerabilities
None known

BG Map Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

BG Map Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
112 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped112 total outputs
Attack Surface

BG Map Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[bg_map_lite] include\shortcode-bg_map.php:5
WordPress Hooks 6
actioninitbg-map.php:43
actionadmin_enqueue_scriptsbg-map.php:53
actionwp_enqueue_scriptsbg-map.php:58
actionadmin_menubg-map.php:64
actionadmin_initbg-map.php:68
actionadmin_headbg-map.php:292
Maintenance & Trust

BG Map Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedNov 15, 2022
PHP min version7.0
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Alternatives

BG Map Alternatives

No alternatives data available yet.

Developer Profile

BG Map Developer Profile

seosbg

74 plugins · 10K total installs

97
trust score
Avg Security Score
95/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect BG Map

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bg-map/css/admin.css/wp-content/plugins/bg-map/js/admin.js/wp-content/plugins/bg-map/css/style.css
Script Paths
/wp-content/plugins/bg-map/js/admin.js

HTML / DOM Fingerprints

CSS Classes
admin-fg-bg_maptable-optionss-fg_bg_map-optionstable-slides-fg_bg_map-numtab-colorreg-title
Data Attributes
id="admin-fg-bg_map"id="loading"class="dent clear"name="link_1"name="link_2"name="link_3"+10 more
Shortcode Output
[bg_map_lite]
FAQ

Frequently Asked Questions about BG Map