
Store Locator Security & Risk Analysis
wordpress.org/plugins/fs-store-locatorStore Locator is the most comprehensive WordPress Store Locator that offers you immediate access to all the stores in your local area with leaflet Map …
Is Store Locator Safe to Use in 2026?
Generally Safe
Score 85/100Store Locator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "fs-store-locator" plugin v1.0.1 presents a mixed security posture. On the positive side, it demonstrates good practices in handling SQL queries, exclusively using prepared statements, and a high percentage of properly escaped outputs. The absence of known CVEs and dangerous functions is also a reassuring sign. However, a significant concern arises from the considerable attack surface exposed without proper authentication. Three out of four entry points, specifically AJAX handlers, lack any form of authorization checks. This creates a direct path for unauthenticated users to interact with potentially sensitive plugin functionalities.
Taint analysis reveals flows with unsanitized paths, although the severity is rated as low, this still indicates a potential for issues if the data is processed in a sensitive manner downstream. The lack of nonce checks on AJAX handlers further exacerbates the risk associated with the unprotected AJAX endpoints, as it opens the door for Cross-Site Request Forgery (CSRF) attacks. The plugin's history of no recorded vulnerabilities is positive, suggesting a generally secure development approach, but this should not overshadow the immediate risks identified in the static analysis.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Missing nonce checks on AJAX handlers
Store Locator Security Vulnerabilities
Store Locator Code Analysis
Output Escaping
Data Flow Analysis
Store Locator Attack Surface
AJAX Handlers 3
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Store Locator Maintenance & Trust
Maintenance Signals
Community Trust
Store Locator Alternatives
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
WP Store Locator
wp-store-locator
An easy to use location management system that enables users to search for nearby physical stores.
MapPress Maps for WordPress
mappress-google-maps-for-wordpress
MapPress is the easiest way to add unlimited interactive Google and Leaflet maps to WordPress.
Store Locator WordPress
agile-store-locator
Agile Store Locator is a premium store finder plugin designed to offer you immediate access to all the best stores in your local area.
Maps Plugin using Google Maps for WordPress – WP Google Map
gmap-embed
Google Map plugin for WordPress is very Simple, light-weight and Easy to use Google Custom Map with markers in Posts, Pages, Sidebar as shortcode.
Store Locator Developer Profile
3 plugins · 10 total installs
How We Detect Store Locator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/fs-store-locator/assets/css/fssl-map.css/wp-content/plugins/fs-store-locator/assets/css/leaflet.css/wp-content/plugins/fs-store-locator/assets/css/leaflet-search.src.css/wp-content/plugins/fs-store-locator/assets/js/fssl-map.js/wp-content/plugins/fs-store-locator/assets/js/leaflet-search.src.js/wp-content/plugins/fs-store-locator/assets/js/leaflet.js/wp-content/plugins/fs-store-locator/assets/js/map-view.js/wp-content/plugins/fs-store-locator/assets/js/admin-map-view.js/wp-content/plugins/fs-store-locator/assets/js/leaflet.js/wp-content/plugins/fs-store-locator/assets/js/fssl-map.js/wp-content/plugins/fs-store-locator/assets/js/leaflet-search.src.js/wp-content/plugins/fs-store-locator/assets/js/map-view.js/wp-content/plugins/fs-store-locator/assets/js/admin-map-view.jsHTML / DOM Fingerprints
fssl-map-wrapperdata-latdata-lngdata-zoomdata-markerfssl_search_by_zipfssl_search_by_leaflet[fssl-store-locator]