
EasyMap Security & Risk Analysis
wordpress.org/plugins/easymapMaps plugin for WordPress with support for Google Maps. Tested with WordPress 5.5+ and PHP 7.4+
Is EasyMap Safe to Use in 2026?
Generally Safe
Score 100/100EasyMap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The easymap plugin v1.1.2 exhibits a mixed security posture. On the positive side, there are no known CVEs, indicating a good track record for security. The absence of critical or high severity taint flows and the presence of nonce and capability checks across most entry points are encouraging signs of secure coding practices. The plugin also appears to be diligent about escaping output and making external HTTP requests, which are important security considerations.
However, there are notable areas for improvement. The most significant concern is the SQL query which is not being prepared. This presents a substantial risk of SQL injection vulnerabilities, especially if the data used in the query originates from user input. Furthermore, the plugin utilizes file operations without clear indications of sanitization in the provided data, which could lead to path traversal vulnerabilities if not handled carefully. While the taint analysis found no critical or high severity issues, the presence of unsanitized paths in two flows suggests a potential for issues that may not have been flagged as critical in this specific analysis but still warrant attention.
In conclusion, easymap v1.1.2 has a generally good foundation with no known historical vulnerabilities and several positive security implementations. However, the lack of prepared statements for its SQL query is a critical oversight that significantly elevates the risk profile. Addressing this, along with ensuring robust sanitization for file operations, is paramount to improving its overall security.
Key Concerns
- SQL queries not using prepared statements
- Flows with unsanitized paths detected
- File operations present without clear sanitization context
EasyMap Security Vulnerabilities
EasyMap Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
EasyMap Attack Surface
Shortcodes 1
WordPress Hooks 13
Maintenance & Trust
EasyMap Maintenance & Trust
Maintenance Signals
Community Trust
EasyMap Alternatives
Kikote – Location Picker at Checkout & Google Address AutoFill Plugin for WooCommerce
map-location-picker-at-checkout-for-woocommerce
Allow customers to select delivery/pickup spots on Google Maps at Checkout. Create shipping workflows for smooth order handling and better pricing.
Track Geolocation Of Users Using Contact Form 7
track-geolocation-of-users-using-contact-form-7
Track Geolocation Of Users Using Contact Form 7 allows you to get geolocation information with their form submission.
Checkout Location Picker for WooCommerce
sg-checkout-location-picker
Sg WooCommerce Checkout Location Picker helps customers to mark their geo location on google map in WooCommerce checkout page.
Simple Fields Map extension
simple-fields-map-extension
Extension to Simple Fields that adds a field type for selecting a location on a Google Map.
Quick Maps
quick-maps
The easiest Google Maps integration for your Wordpress website [quick-maps]Orlando, Florida[/quick-maps] - No Google API required.
EasyMap Developer Profile
5 plugins · 190 total installs
How We Detect EasyMap
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/easymap/css/easymap.css/wp-content/plugins/easymap/js/easymap.js/wp-content/plugins/easymap/css/admin.css/wp-content/plugins/easymap/js/admin.js/wp-content/plugins/easymap/js/easymap-map-block.js/wp-content/plugins/easymap/js/easymap-map-block.asset.php/wp-content/plugins/easymap/js/easymap.js/wp-content/plugins/easymap/js/admin.js/wp-content/plugins/easymap/js/easymap-map-block.jseasymap/css/easymap.css?ver=easymap/js/easymap.js?ver=easymap/css/admin.css?ver=easymap/js/admin.js?ver=easymap/js/easymap-map-block.js?ver=HTML / DOM Fingerprints
easymap-content-wrappereasymap-map-containereasymap-location-listeasymap-location-item<!-- EasyMap: start-template --><!-- EasyMap: end-template --><!-- EasyMap: admin-css --><!-- EasyMap: admin-js -->data-easymap-noncedata-easymap-ajaxurldata-easymap-mapiddata-easymap-latdata-easymap-lngdata-easymap-zoom+1 moreeasymap_varseasymap_localize_data[easymap[easymap_location_list