
Click to map for Elementor Security & Risk Analysis
wordpress.org/plugins/click-to-map-for-elementorElementor control that will load a Google Maps iframe after clicking "accept" - no external data is loaded before clicking it.
Is Click to map for Elementor Safe to Use in 2026?
Generally Safe
Score 100/100Click to map for Elementor has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'click-to-map-for-elementor' v1.2.2 exhibits a very strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code demonstrates good practices by not utilizing dangerous functions, performing file operations, or making external HTTP requests. The fact that all SQL queries use prepared statements is also a positive indicator of secure coding. The lack of any recorded vulnerabilities, including CVEs, further reinforces this strong security standing.
However, a few areas warrant careful consideration. The analysis shows a concerning absence of nonce checks and capability checks across all entry points. While the current entry point count is zero, if any were to be introduced without proper authorization, this lack of checks could present a significant risk. Additionally, 25% of output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved in these outputs. The lack of taint analysis results is also noteworthy; while it might indicate no flows were found, it could also mean the analysis itself was limited.
Overall, the plugin is commendably secure in its current state, with no identified vulnerabilities and a limited attack surface. The developers have demonstrated good practices regarding SQL and dangerous functions. The primary weaknesses lie in the potential for future vulnerabilities due to the lack of authorization checks on potential entry points and the presence of unescaped output. These are areas to monitor closely should the plugin be updated or expanded.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Unescaped output (1 out of 4)
Click to map for Elementor Security Vulnerabilities
Click to map for Elementor Code Analysis
Output Escaping
Click to map for Elementor Attack Surface
WordPress Hooks 2
Maintenance & Trust
Click to map for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Click to map for Elementor Alternatives
Qi Addons For Elementor
qi-addons-for-elementor
Qi Addons for Elementor is a comprehensive library of 60+ custom, flexible & easily styled Elementor widgets developed by Qode Interactive.
Mega Elements – Addons for Elementor
mega-elements-addons-for-elementor
A powerful and advanced all in one Elementor addons with unique styling features to create a beautiful website effortlessly.
ElementsReady Addons for Elementor
element-ready-lite
ElementsReady Addons for Elementor comes up with ultimate widgets like Post, Accordion, Portfolio, Testimonial, Nav menu, Carousel, Slider etc..
MT Addons for Elementor
mt-addons-for-elementor
MT Addons for Elementor with 50+ widgets, crafted by ModelTheme for dynamic, stylish website creation.
Easy Elements for Elementor – Addons & Website Templates
easy-elements
Modern Elementor Addons: A lightweight, powerful addon with beautifully designed widgets and extensions to build creative, animated websites.
Click to map for Elementor Developer Profile
7 plugins · 10K total installs
How We Detect Click to map for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/click-to-map-for-elementor/styles/main.cssHTML / DOM Fingerprints
click__mapclick__map__text__contentdata-elementor-open-widget-settings