Geo hCard Map Security & Risk Analysis

wordpress.org/plugins/geo-hcard-map

[geo_hcard_map] map of hCard elements found in the current webpage.

10 active installs v1.0 PHP + WP 4.0+ Updated Unknown
hcardleafletlocationmaposm
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Geo hCard Map Safe to Use in 2026?

Generally Safe

Score 100/100

Geo hCard Map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The static analysis of the "geo-hcard-map" plugin v1.0 indicates a strong security posture. There are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the plugin's attack surface. Furthermore, the code demonstrates good security practices, with all SQL queries utilizing prepared statements and all outputs being properly escaped. The absence of dangerous functions, file operations, external HTTP requests, and the lack of bundled libraries further contribute to a secure foundation. The taint analysis reveals no flows with unsanitized paths, indicating a lack of common injection vulnerabilities. The vulnerability history is also clean, with no recorded CVEs, suggesting a history of secure development and maintenance.

While the current analysis shows no immediate risks, the complete absence of capability checks and nonce checks on any potential (though currently nonexistent) entry points is a notable concern. Should new entry points be introduced in future versions without proper authorization and security checks, it could lead to vulnerabilities. The current lack of any identified vulnerabilities or insecure code patterns is a significant strength. However, the absence of these common security mechanisms is a weakness that could be exploited if the plugin's architecture were to change in a way that exposes these areas without adequate protection.

Key Concerns

  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

Geo hCard Map Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Geo hCard Map Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Geo hCard Map Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menugeo-hcard-map.php:22
actionadmin_initgeo-hcard-map.php:23
actionadmin_enqueue_scriptsgeo-hcard-map.php:81
actionwp_enqueue_scriptsgeo-hcard-map.php:93
actionwp_enqueue_scriptsgeo-hcard-map.php:100
actionplugins_loadedgeo-hcard-map.php:105
actionadmin_noticesgeo-hcard-map.php:157
Maintenance & Trust

Geo hCard Map Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Geo hCard Map Developer Profile

anewholm

2 plugins · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Geo hCard Map

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/geo-hcard-map/js/admin.js/wp-content/plugins/geo-hcard-map/css/admin.css/wp-content/plugins/geo-hcard-map/js/options.js/wp-content/plugins/geo-hcard-map/leaflet/leaflet.js/wp-content/plugins/geo-hcard-map/js/map.js/wp-content/plugins/geo-hcard-map/leaflet/leaflet.css/wp-content/plugins/geo-hcard-map/css/style.css
Script Paths
js/admin.jsjs/options.jsleaflet/leaflet.jsjs/map.js
Version Parameters
geo-hcard-map/js/admin.js?ver=geo-hcard-map/css/admin.css?ver=geo-hcard-map/leaflet/leaflet.js?ver=geo-hcard-map/js/map.js?ver=geo-hcard-map/leaflet/leaflet.css?ver=geo-hcard-map/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
shortcodes-listgeo-hcard-map-ajaxsubmittingsuccess
Data Attributes
geo_hcard_map_settings[geo_hcard_map_type]
JS Globals
geo_hcard_map_settings
Shortcode Output
<div id="geo-hcard-map">&nbsp;</div>
FAQ

Frequently Asked Questions about Geo hCard Map