Geo Map Locations WordPress Plugin Security & Risk Analysis

wordpress.org/plugins/geo-multi-location-map

Geo Map Locations plugin Display multi location with description and image on single page.

20 active installs v1.1.2 PHP + WP 3.8+ Updated May 14, 2017
easy-to-use-with-just-place-short-code-on-anywheregeo-mapgeo-map-locationslocationstag-places
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Geo Map Locations WordPress Plugin Safe to Use in 2026?

Generally Safe

Score 85/100

Geo Map Locations WordPress Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The 'geo-multi-location-map' plugin version 1.1.2 presents a mixed security posture. While the plugin boasts no known CVEs and has a limited attack surface with no unprotected entry points, the static analysis reveals several areas for concern. A significant portion of SQL queries are not prepared, and a substantial percentage of output is not properly escaped, indicating potential vulnerabilities. The taint analysis further highlights this with two high-severity flows involving unsanitized paths, which could lead to path traversal or file inclusion vulnerabilities if exploited.

The lack of reported historical vulnerabilities is a positive sign, suggesting the developers may have a good understanding of WordPress security. However, the presence of high-severity taint flows in the current analysis, combined with the insecure handling of SQL and output, suggests that the absence of past vulnerabilities may be due to a lack of targeted exploitation rather than robust security practices. The plugin's strengths lie in its controlled entry points and the absence of known CVEs, but these are overshadowed by the identified code-level risks that require immediate attention.

Key Concerns

  • High severity taint flows detected
  • SQL queries not using prepared statements
  • Output not properly escaped
  • Lack of capability checks
Vulnerabilities
None known

Geo Map Locations WordPress Plugin Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Geo Map Locations WordPress Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
19
6 prepared
Unescaped Output
31
44 escaped
Nonce Checks
2
Capability Checks
0
File Operations
4
External Requests
0
Bundled Libraries
0

SQL Query Safety

24% prepared25 total queries

Output Escaping

59% escaped75 total outputs
Data Flows
3 unsanitized

Data Flow Analysis

5 flows3 with unsanitized paths
gmlm_page_handler (geomap.php:328)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Geo Map Locations WordPress Plugin Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[geo_map] geomap.php:70
WordPress Hooks 2
actioninitgeomap.php:72
actionadmin_menugeomap.php:82
Maintenance & Trust

Geo Map Locations WordPress Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested4.7.32
Last updatedMay 14, 2017
PHP min version
Downloads7K

Community Trust

Rating100/100
Number of ratings3
Active installs20
Developer Profile

Geo Map Locations WordPress Plugin Developer Profile

omexinfotech

1 plugin · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Geo Map Locations WordPress Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/geo-multi-location-map/css/location.css/wp-content/plugins/geo-multi-location-map/css/geomap.css/wp-content/plugins/geo-multi-location-map/js/location.js/wp-content/plugins/geo-multi-location-map/js/mapview.js/wp-content/plugins/geo-multi-location-map/js/confrm.js
Script Paths
http://maps.googleapis.com/maps/api/js?key=$api&sensor=false
Version Parameters
geo-multi-location-map/css/location.css?ver=geo-multi-location-map/css/geomap.css?ver=geo-multi-location-map/js/location.js?ver=geo-multi-location-map/js/mapview.js?ver=geo-multi-location-map/js/confrm.js?ver=

HTML / DOM Fingerprints

CSS Classes
gmlm_data
Data Attributes
data-postid
JS Globals
gmlm_versiongmlm_data
Shortcode Output
[geo_map]
FAQ

Frequently Asked Questions about Geo Map Locations WordPress Plugin