
F13 Google Maps Security & Risk Analysis
wordpress.org/plugins/f13-google-maps-shortcodeIf you own a shop, host events, or have any other need to add a google map reference to your WordPress blog, try F13 Google Maps Shortcode.
Is F13 Google Maps Safe to Use in 2026?
Generally Safe
Score 85/100F13 Google Maps has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "f13-google-maps-shortcode" plugin v2.0.1 exhibits a generally good security posture based on the provided static analysis. The absence of any known CVEs, critical taint flows, or dangerous functions is a significant strength. Furthermore, the use of prepared statements for all SQL queries and the limited number of entry points are positive indicators. However, there are areas for improvement that introduce potential risks. The plugin has a notable lack of capability checks and nonce checks, which are crucial for securing entry points, even though the current analysis shows zero unprotected entry points. Additionally, a significant portion of output is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if the unescaped output contains user-controlled data. The single external HTTP request also warrants scrutiny to ensure it is handled securely.
Key Concerns
- Missing capability checks
- Missing nonce checks
- Insufficient output escaping (40% unescaped)
- External HTTP request without clear security context
F13 Google Maps Security Vulnerabilities
F13 Google Maps Code Analysis
Output Escaping
F13 Google Maps Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
F13 Google Maps Maintenance & Trust
Maintenance Signals
Community Trust
F13 Google Maps Alternatives
API KEY for Google Maps
api-key-for-google-maps
Retroactively add Google Maps API KEY to any theme or plugin.
Simple Map
simple-map
Easy way to embed google map(s).
Simple Shortcode for Google Maps
simple-google-maps-short-code
A simple shortcode for embedding Google Maps in any WordPress post, page or widget.
Vanilla Adaptive Maps
vanilla-adaptive-maps
Map any address with a shortcode. Mobile users get a static map; desktop users will see a google map.
WP Job Manager Client-Side Geocoder
wp-job-manager-client-side-geocoder
Use client-side geocoding to overcome the OVER_QUERY_LIMIT ( failed to geocode a location ) issue when updating job's location
F13 Google Maps Developer Profile
8 plugins · 90 total installs
How We Detect F13 Google Maps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/f13-google-maps-shortcode/css/google-maps.cssf13-google-maps-shortcode/css/google-maps.css?ver=HTML / DOM Fingerprints
f13-google-maps-error<div class="f13-google-maps-error">