
Easy Map – Store Locator, Google Maps, OpenStreetMap, Leaflet Map Security & Risk Analysis
wordpress.org/plugins/easy-mapCreate interactive maps with store locator, markers, drawings & multiple locations. Supports OpenStreetMap and Google Maps. No API key needed.
Is Easy Map – Store Locator, Google Maps, OpenStreetMap, Leaflet Map Safe to Use in 2026?
Generally Safe
Score 100/100Easy Map – Store Locator, Google Maps, OpenStreetMap, Leaflet Map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "easy-map" v1.8.10 plugin exhibits a generally strong security posture with a significant emphasis on secure coding practices. The static analysis reveals a near-perfect implementation of output escaping and a high percentage of prepared statements for SQL queries. The absence of file operations and external HTTP requests further bolsters its security. Additionally, the plugin demonstrates a robust use of nonce and capability checks for its entry points, with all AJAX handlers and REST API routes appearing to have appropriate authorization. The vulnerability history being entirely clear is a positive indicator, suggesting a proactive approach to security or a lack of past exploitable flaws.
However, a critical concern arises from the taint analysis, which identified 10 flows with unsanitized paths, four of which are classified as high severity. This indicates a potential for vulnerabilities where user-supplied data might be processed without adequate sanitization, leading to unexpected behavior or potential exploits, even if direct critical vulnerabilities were not found. The presence of the `unserialize` function, although not explicitly flagged as a direct exploit in this analysis, is often a vector for deserialization vulnerabilities if used with untrusted input. The large number of shortcodes also contributes to a broader attack surface, although the static analysis did not reveal any direct security issues with them in this version.
In conclusion, "easy-map" v1.8.10 has many strengths in its security implementation, particularly in preventing common web vulnerabilities like XSS and SQL injection through proper escaping and prepared statements. The clear vulnerability history is commendable. The primary risk lies in the identified unsanitized paths in the taint analysis, which warrants careful review and remediation. The presence of `unserialize` also suggests a potential area for deeper scrutiny.
Key Concerns
- High severity taint flows with unsanitized paths
- Flows with unsanitized paths
- Dangerous function used (unserialize)
- Bundled library (Select2)
Easy Map – Store Locator, Google Maps, OpenStreetMap, Leaflet Map Security Vulnerabilities
Easy Map – Store Locator, Google Maps, OpenStreetMap, Leaflet Map Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Easy Map – Store Locator, Google Maps, OpenStreetMap, Leaflet Map Attack Surface
AJAX Handlers 5
REST API Routes 2
Shortcodes 12
WordPress Hooks 13
Maintenance & Trust
Easy Map – Store Locator, Google Maps, OpenStreetMap, Leaflet Map Maintenance & Trust
Maintenance Signals
Community Trust
Easy Map – Store Locator, Google Maps, OpenStreetMap, Leaflet Map Alternatives
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
MapPress Maps for WordPress
mappress-google-maps-for-wordpress
MapPress is the easiest way to add unlimited interactive Google and Leaflet maps to WordPress.
Maps Plugin using Google Maps for WordPress – WP Google Map
gmap-embed
Google Map plugin for WordPress is very Simple, light-weight and Easy to use Google Custom Map with markers in Posts, Pages, Sidebar as shortcode.
Out of the Block: OpenStreetMap
ootb-openstreetmap
A map block for Gutenberg using OpenStreetMap and Leaflet that needs no API keys and works out of the box. Or should we say, ...Out of the Block?
Map Engine – Google Maps and Open Street Maps for WordPress
map-engine
An Ultimate map tool to revolutionize your map building experience.
Easy Map – Store Locator, Google Maps, OpenStreetMap, Leaflet Map Developer Profile
4 plugins · 90 total installs
How We Detect Easy Map – Store Locator, Google Maps, OpenStreetMap, Leaflet Map
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easy-map/admin/css/easy-map-admin.css/wp-content/plugins/easy-map/admin/js/easy-map-admin.js/wp-content/plugins/easy-map/public/css/easy-map-public.css/wp-content/plugins/easy-map/public/js/easy-map-public.js/wp-content/plugins/easy-map/assets/css/bootstrap.min.css/wp-content/plugins/easy-map/assets/css/jquery-ui.css/wp-content/plugins/easy-map/assets/css/leaflet.css/wp-content/plugins/easy-map/assets/css/style.css+12 more/wp-content/plugins/easy-map/admin/js/easy-map-admin.js/wp-content/plugins/easy-map/public/js/easy-map-public.jseasy-map/admin/css/easy-map-admin.css?ver=easy-map/admin/js/easy-map-admin.js?ver=easy-map/public/css/easy-map-public.css?ver=easy-map/public/js/easy-map-public.js?ver=easy-map/assets/css/bootstrap.min.css?ver=easy-map/assets/css/jquery-ui.css?ver=easy-map/assets/css/leaflet.css?ver=easy-map/assets/css/style.css?ver=easy-map/assets/css/swiper.min.css?ver=easy-map/assets/js/bootstrap.min.js?ver=easy-map/assets/js/custom.js?ver=easy-map/assets/js/jquery-3.6.0.min.js?ver=easy-map/assets/js/jquery-ui.js?ver=easy-map/assets/js/leaflet.js?ver=easy-map/assets/js/leaflet.markercluster.js?ver=easy-map/assets/js/marker.js?ver=easy-map/assets/js/script.js?ver=easy-map/assets/js/swiper.min.js?ver=easy-map/assets/js/waypoints.min.js?ver=HTML / DOM Fingerprints
easy-map-wrappereasy-map-mapem-map-containereasy-map-markerseasy-map-markereasy-map-store-locatoreasy-map-admin-wrap<!-- Easy Map plugin --><!-- Start Easy Map --><!-- End Easy Map --><!-- Easy Map Admin Page -->data-easy-map-iddata-map-settingsdata-marker-dataeasyMapSettingseasyMapAdminDataeasyMapPublicData/wp-json/easy-map/v1/settings//wp-json/easy-map/v1/maps/<div class="easy-map-wrapper"<div id="easy-map-<div class="em-map-container"