
Custom Post Type to Map Store Security & Risk Analysis
wordpress.org/plugins/cpt-to-map-storeAn another Store Locator on WordPress but with OpenStreetMap & Leaflet and Meta Fields
Is Custom Post Type to Map Store Safe to Use in 2026?
Use With Caution
Score 64/100Custom Post Type to Map Store has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "cpt-to-map-store" plugin v1.1.0 exhibits a mixed security posture. On one hand, the static analysis shows no identified entry points (AJAX, REST API, shortcodes, cron events) that are directly exposed without authentication or permission checks, which is a positive sign. Furthermore, all SQL queries are properly prepared, and there are no file operations or external HTTP requests, reducing common attack vectors. However, the presence of the `unserialize` function is a significant concern, as it can lead to Remote Code Execution (RCE) if an attacker can control the serialized data. The lack of nonce checks and capability checks further exacerbates this risk, as there are no mechanisms to verify user intent or authorization before potentially dangerous operations are executed.
The vulnerability history reveals a past medium severity CVE, specifically a Cross-Site Request Forgery (CSRF). The fact that this vulnerability is currently unpatched is a critical red flag, indicating an ongoing risk that has not been addressed by the developer. This pattern of past vulnerabilities, coupled with the current unpatched issue, suggests a potential lack of ongoing security maintenance and a tendency for vulnerabilities to remain unresolved, which is a concerning indicator for future security. While the attack surface appears limited and some good coding practices are present, the `unserialize` function in conjunction with missing security checks and an unpatched CVE presents a tangible risk to users of this plugin.
Key Concerns
- Unpatched Medium Severity CVE
- Dangerous function: unserialize
- Missing nonce checks
- Missing capability checks
- Output escaping not fully proper (41% not escaped)
Custom Post Type to Map Store Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Custom Post Type to Map Store <= 1.1.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Custom Post Type to Map Store Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Custom Post Type to Map Store Attack Surface
WordPress Hooks 8
Maintenance & Trust
Custom Post Type to Map Store Maintenance & Trust
Maintenance Signals
Community Trust
Custom Post Type to Map Store Alternatives
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
WP Open Street Map
wp-open-street-map
Create easily maps with OpenStreetMap
MIPL Stockist/Store Locator
mipl-stockist-store-locator
Create a quick Stockist/Store Locator with Google Map, Autocomplete search location & Distance & Category filter.
Easy Map – Store Locator, Google Maps, OpenStreetMap, Leaflet Map
easy-map
Create interactive maps with store locator, markers, drawings & multiple locations. Supports OpenStreetMap and Google Maps. No API key needed.
WP Store Locator
wp-store-locator
An easy to use location management system that enables users to search for nearby physical stores.
Custom Post Type to Map Store Developer Profile
1 plugin · 40 total installs
How We Detect Custom Post Type to Map Store
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cpt-to-map-store/assets/css/admin.css/wp-content/plugins/cpt-to-map-store/assets/js/admin.js/wp-content/plugins/cpt-to-map-store/assets/js/admin.jscpt-to-map-store/assets/css/admin.css?ver=cpt-to-map-store/assets/js/admin.js?ver=HTML / DOM Fingerprints
cpt-to-map-store-settings<!-- HELP: https://codex.wordpress.org/Validating_Sanitizing_and_Escaping_User_Data -->data-id_setting_pageCpt_To_Map_Store