
Custom WP Store Locator Security & Risk Analysis
wordpress.org/plugins/custom-store-locatorCreate and manage multiple locations on Map. you can use a search widget, store locator map, category filter, and near location finder features.
Is Custom WP Store Locator Safe to Use in 2026?
Generally Safe
Score 99/100Custom WP Store Locator has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of "custom-store-locator" v1.5.1.2 reveals a generally good security posture with several strengths. The plugin demonstrates strong practices by utilizing prepared statements for all SQL queries and having a high percentage of properly escaped output. It also correctly implements nonce and capability checks, and has no external HTTP requests or dangerous function calls. The absence of critical and high severity taint flows is also a positive indicator. However, the presence of 2 shortcodes represents a potential attack surface, although currently none are identified as unprotected. The plugin's vulnerability history shows one past medium severity CVE, which has been patched, indicating that the developers have addressed security issues. The last vulnerability being in the future suggests a placeholder or an error in the provided data, but if taken at face value, it means there are no currently unpatched vulnerabilities.
Despite the positive aspects, the 293 total outputs with 11% unescaped, while not critically high, still represent a potential vector for cross-site scripting (XSS) if user-supplied data is involved in those outputs. The existence of file operations without further context also warrants careful review. The vulnerability history, though indicating a patched medium vulnerability, suggests that the plugin has had security flaws in the past, necessitating ongoing vigilance. Overall, the plugin exhibits good security hygiene but has minor areas for improvement, particularly concerning the potential for XSS in the small percentage of unescaped outputs and the presence of shortcodes as entry points.
Key Concerns
- Unescaped output found
- Potential for XSS based on past CVE
- Presence of shortcodes as entry points
Custom WP Store Locator Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Custom WP Store Locator <= 1.4.7 - Reflected Cross-Site SCripting
Custom WP Store Locator Code Analysis
Output Escaping
Data Flow Analysis
Custom WP Store Locator Attack Surface
Shortcodes 2
WordPress Hooks 21
Maintenance & Trust
Custom WP Store Locator Maintenance & Trust
Maintenance Signals
Community Trust
Custom WP Store Locator Alternatives
WP Store Locator
wp-store-locator
An easy to use location management system that enables users to search for nearby physical stores.
Store Locator WordPress
agile-store-locator
Agile Store Locator is a premium store finder plugin designed to offer you immediate access to all the best stores in your local area.
Store Locator for WordPress📍
storelocator
Create a store locator for your website in minutes. Add all the store locations in google sheets and embed map on your website.
Store Locator with Google Map
store-locator-with-google-map
Now your customers can find your location easily with our simple, free Google Maps one store locator. Customizable and Responsive.
PTI Store Locator
pti-store-locator
Display multiple store or branch locations on Google Maps with search, filters, and customizable info windows.
Custom WP Store Locator Developer Profile
1 plugin · 300 total installs
How We Detect Custom WP Store Locator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/custom-store-locator/assets/css/admin.css/wp-content/plugins/custom-store-locator/assets/css/frontend.css/wp-content/plugins/custom-store-locator/assets/js/admin.js/wp-content/plugins/custom-store-locator/assets/js/frontend.js/wp-content/plugins/custom-store-locator/assets/js/frontend.jscustom-store-locator/assets/css/admin.css?ver=custom-store-locator/assets/css/frontend.css?ver=custom-store-locator/assets/js/admin.js?ver=custom-store-locator/assets/js/frontend.js?ver=HTML / DOM Fingerprints
csl-map-containerdata-csl-map-api-keydata-csl-map-default-radiusdata-csl-primary-colordata-csl-secondary-colorCSL_DATA/wp-json/custom-store-locator/v1/locations[csl_map][csl_search]