Events Manager OpenStreetMap Security & Risk Analysis

wordpress.org/plugins/events-manager-openstreetmap

Events Manager OpenStreetMap is a WordPress plugin for Events Manager. It allows you to replace Google Maps to OpenStreetMap on all your event locatio …

100 active installs v2.0.7 PHP + WP 3.0+ Updated Feb 12, 2024
events-managermapmoduleopenstreetmap
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Events Manager OpenStreetMap Safe to Use in 2026?

Generally Safe

Score 85/100

Events Manager OpenStreetMap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

The "events-manager-openstreetmap" plugin v2.0.7 exhibits a generally good security posture based on the provided static analysis. The absence of known vulnerabilities, a clean taint analysis with no critical or high severity flows, and the predominant use of prepared statements for SQL queries are strong indicators of secure development practices. The code also demonstrates attention to security by implementing nonce checks and capability checks, along with a high percentage of properly escaped output, minimizing the risk of common web vulnerabilities like Cross-Site Scripting (XSS). However, the presence of two shortcodes as entry points, while currently unprotected by explicit authorization checks in the static analysis, presents a potential, albeit small, attack surface if not handled with care within their implementation. The plugin's history of zero recorded CVEs is a significant positive, suggesting a track record of security awareness and maintenance. Overall, the plugin appears to be developed with security in mind, with its strengths largely outweighing its minor potential concerns. Further review of the shortcode implementations would be beneficial for complete assurance.

Key Concerns

  • Shortcodes without explicit auth checks
Vulnerabilities
None known

Events Manager OpenStreetMap Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Events Manager OpenStreetMap Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
240 escaped
Nonce Checks
1
Capability Checks
2
File Operations
14
External Requests
0
Bundled Libraries
0

Output Escaping

94% escaped254 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
<settings> (admin\settings.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Events Manager OpenStreetMap Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[em_osmap] includes\map.php:368
[em_osmap_categories] includes\map.php:461
WordPress Hooks 24
actionadmin_menuclasses\class.php:19
actionadmin_enqueue_scriptsclasses\class.php:20
actionwp_enqueue_scriptsclasses\class.php:21
filterplugin_action_linksclasses\class.php:22
actionwp_headclasses\class.php:23
filtermanage_edit-location_columnsclasses\class.php:25
actionmanage_location_posts_custom_columnclasses\class.php:26
filtermanage_edit-event_columnsclasses\class.php:28
actionmanage_event_posts_custom_columnclasses\class.php:29
filtermanage_edit-event-categories_columnsclasses\class.php:31
actionmanage_event-categories_custom_columnclasses\class.php:32
actionplugins_loadedevents-manager-openstreetmap.php:38
actionadmin_noticesevents-manager-openstreetmap.php:53
actioninitevents-manager-openstreetmap.php:56
filterem_event_output_placeholderincludes\map.php:138
filterem_location_output_placeholderincludes\map.php:139
actionadmin_menuincludes\metabox.php:8
actionsave_postincludes\metabox.php:102
actionsave_postincludes\metabox.php:390
actionevent-categories_add_form_fieldsincludes\taxonomy.php:21
actioncreated_event-categoriesincludes\taxonomy.php:22
actionevent-categories_edit_form_fieldsincludes\taxonomy.php:23
actionedited_event-categoriesincludes\taxonomy.php:24
actionadmin_enqueue_scriptsincludes\taxonomy.php:25
Maintenance & Trust

Events Manager OpenStreetMap Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedFeb 12, 2024
PHP min version
Downloads6K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Events Manager OpenStreetMap Developer Profile

Florent Maillefaud

4 plugins · 59K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
398 days
View full developer profile
Detection Fingerprints

How We Detect Events Manager OpenStreetMap

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/events-manager-openstreetmap/css/em-osm.css/wp-content/plugins/events-manager-openstreetmap/js/leaflet.js/wp-content/plugins/events-manager-openstreetmap/js/em-osm.js
Script Paths
/wp-content/plugins/events-manager-openstreetmap/js/leaflet.js/wp-content/plugins/events-manager-openstreetmap/js/em-osm.js
Version Parameters
events-manager-openstreetmap/css/em-osm.css?ver=events-manager-openstreetmap/js/leaflet.js?ver=events-manager-openstreetmap/js/em-osm.js?ver=

HTML / DOM Fingerprints

CSS Classes
em-osm-thumbnailem-osm-contentem-osm-readmoreem-osm-event-contentem-osm-event-readmoreem-osm-single-thumbnailem-osm-single-contentem-osm-single-readmore+5 more
Data Attributes
data-osm_latdata-osm_lngdata-osm_zoomdata-osm_icondata-osm_icon_size_widthdata-osm_icon_size_height+21 more
JS Globals
EMOSM_VERSION
FAQ

Frequently Asked Questions about Events Manager OpenStreetMap