Gmap Block Security & Risk Analysis

wordpress.org/plugins/gmap-block

Easily Embed Google map in Gutenberg editor without any API key.

10K active installs v1.2.3 PHP 7.4+ WP 6.0+ Updated Mar 24, 2026
gmap-blockgoogle-mapgutenbergmapmap-block
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Gmap Block Safe to Use in 2026?

Generally Safe

Score 100/100

Gmap Block has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the gmap-block plugin v1.2.3 exhibits a strong security posture. The code analysis reveals no detectable attack surface through common entry points like AJAX handlers, REST API routes, shortcodes, or cron events. Furthermore, the code demonstrates excellent practice by having zero dangerous functions, zero file operations, zero external HTTP requests, and a complete absence of SQL queries that are not prepared statements. Output is also 100% properly escaped, and critical security features like nonce and capability checks are consistently absent, which is concerning as it implies no checks are needed because there are no entry points to protect. The vulnerability history is also clean, with zero known CVEs of any severity and no recorded common vulnerability types. This suggests a well-developed and secure plugin. However, the complete lack of any entry points or protective checks, while seemingly secure, is unusual. It raises questions about the plugin's actual functionality and whether it's intended to be used at all in its current form, or if there's a possibility of entry points being missed by the analysis. The absence of these checks, while not directly indicating a vulnerability in this specific analysis, points to a potential weakness if the plugin were to gain any functional entry points in the future.

Key Concerns

  • Missing nonce checks implies lack of protection
  • Missing capability checks implies lack of protection
Vulnerabilities
None known

Gmap Block Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Gmap Block Release Timeline

v1.2.3Current
v1.2.2
v1.2.1
v1.2.0
v1.1.0
v1.0.5
v1.0.4
v1.0.3
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Apr 16, 2026

Gmap Block Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Gmap Block Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
filterrender_blockinc/classes/dynamic-style.php:43
actionwp_enqueue_scriptsinc/classes/dynamic-style.php:46
actionenqueue_block_editor_assetsinc/classes/enqueue-assets.php:40
actioninitinc/classes/register-blocks.php:40
Maintenance & Trust

Gmap Block Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 24, 2026
PHP min version7.4
Downloads60K

Community Trust

Rating100/100
Number of ratings2
Active installs10K
Developer Profile

Gmap Block Developer Profile

Binsaifullah

5 plugins · 27K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
10 days
View full developer profile
Detection Fingerprints

How We Detect Gmap Block

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gmap-block/build/global/index.js/wp-content/plugins/gmap-block/build/global/index.css/wp-content/plugins/gmap-block/build/modules/index.js
Script Paths
/wp-content/plugins/gmap-block/build/global/index.js/wp-content/plugins/gmap-block/build/modules/index.js
Version Parameters
gmap-block-global-script?ver=gmap-block-global-style?ver=gmap-block-module-script?ver=

HTML / DOM Fingerprints

JS Globals
gmapBlockPro
FAQ

Frequently Asked Questions about Gmap Block