Find Us At Security & Risk Analysis

wordpress.org/plugins/findusat

Quickly display a map of the locations that your product is in or were your stores are located.

0 active installs v1.2.1 PHP 5.2.4+ WP 4.9+ Updated Oct 15, 2018
brick-mortardealershipslocationsstore-locationwhere-to-find-us
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Find Us At Safe to Use in 2026?

Generally Safe

Score 85/100

Find Us At has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "findusat" plugin v1.2.1 exhibits a mixed security posture. On the positive side, it has no recorded vulnerabilities (CVEs) and its SQL queries are all properly prepared, indicating good practices in database interaction. Furthermore, it doesn't make external HTTP requests, which mitigates risks associated with remote code execution or data exfiltration through external services.

However, significant security concerns arise from its attack surface. With 3 out of 5 entry points lacking authentication checks (AJAX handlers), there's a high risk of unauthorized actions or information disclosure. The plugin also has a low rate of proper output escaping (42%), suggesting potential for cross-site scripting (XSS) vulnerabilities where user-supplied data might be rendered directly in the browser without proper sanitization. The absence of nonce checks on its AJAX handlers further exacerbates these risks by allowing for cross-site request forgery (CSRF) attacks.

While the plugin has a clean vulnerability history, this cannot be relied upon to guarantee future security. The presence of critical weaknesses like unprotected AJAX endpoints and insufficient output escaping means the plugin is susceptible to exploitation even without prior recorded vulnerabilities. The overall assessment leans towards a moderate to high risk due to the exploitable attack surface and potential for XSS, despite the absence of known CVEs and secure SQL practices.

Key Concerns

  • Unprotected AJAX handlers
  • Insufficient output escaping
  • Missing nonce checks on AJAX
  • Large attack surface without auth
Vulnerabilities
None known

Find Us At Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Find Us At Release Timeline

v1.2.1Current
v1.2
v1.1
Code Analysis
Analyzed Mar 17, 2026

Find Us At Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
7
5 escaped
Nonce Checks
0
Capability Checks
1
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

42% escaped12 total outputs
Attack Surface
3 unprotected

Find Us At Attack Surface

Entry Points5
Unprotected3

AJAX Handlers 3

authwp_ajax_get_coordinates_for_shortcodefindusat.php:20
noprivwp_ajax_get_coordinates_for_shortcodefindusat.php:21
authwp_ajax_getCoordinatesfindusat.php:200

Shortcodes 2

[findusat] findusat.php:13
[findusat_locations] findusat.php:14
WordPress Hooks 7
actionadmin_menufindusat.php:16
actionwp_enqueue_scriptsfindusat.php:17
actionadmin_enqueue_scriptsfindusat.php:18
actioninitfindusat.php:98
actionadd_meta_boxesfindusat.php:107
actionsave_postfindusat.php:162
actionadmin_initinclude\findusat_admin_settings.php:66
Maintenance & Trust

Find Us At Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedOct 15, 2018
PHP min version5.2.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Find Us At Developer Profile

hypertextstudios

2 plugins · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Find Us At

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/findusat/assets/css/findusat.css/wp-content/plugins/findusat/assets/css/admin_findusat.css
Script Paths
https://maps.googleapis.com/maps/api/js?key=/wp-content/plugins/findusat/assets/js/findusat.js/wp-content/plugins/findusat/assets/js/admin_findusat.js
Version Parameters
findusat.css?ver=admin_findusat.css?ver=findusat.js?ver=admin_findusat.js?ver=

HTML / DOM Fingerprints

CSS Classes
address_line_1address_line_2submit_addressfindusat_map
HTML Comments
<!-- generate coordinates -->
Data Attributes
name="address_line_1"name="address_line_2"class="submit_address"id="x_coordinate"id="y_coordinate"id="mapsLink"+1 more
JS Globals
fua_coords
REST Endpoints
/wp-json/wp/v2/location
Shortcode Output
<div id="findusat_map"<ul id="findusat_locations">
FAQ

Frequently Asked Questions about Find Us At