
GMap Targeting – Simple Targeting Inside Google Maps Security & Risk Analysis
wordpress.org/plugins/gmap-targetingSet Google Map everywhere by shortcode on your WordPress site simply. One click - one map! This lightweight plugin is managed in an intuitive way.
Is GMap Targeting – Simple Targeting Inside Google Maps Safe to Use in 2026?
Generally Safe
Score 94/100GMap Targeting – Simple Targeting Inside Google Maps has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The gmap-targeting plugin v1.1.8 exhibits a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and includes nonce and capability checks on its single AJAX entry point, significant concerns arise from its output escaping and historical vulnerability data. Only 3% of outputs are properly escaped, suggesting a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's history of XSS CVEs. The presence of file operations and external HTTP requests, without explicit mention of sanitization in the static analysis, also warrants caution.
The vulnerability history is a major red flag. The plugin has a past of two high-severity CVEs, including Cross-Site Scripting and PHP Remote File Inclusion, with the most recent recorded vulnerability in 2026. Although currently unpatched CVEs are reported as 0, the recurrence of critical vulnerability types and the relatively recent past vulnerability indicate potential for future exploitable flaws. This history, coupled with the poor output escaping, creates a significant risk profile.
In conclusion, while the plugin has made some positive strides in secure coding practices like prepared statements and basic authentication checks, the pervasive lack of output escaping and the history of severe vulnerabilities, particularly PHP Remote File Inclusion and XSS, present a substantial security risk. Users should be extremely cautious and ensure the plugin is updated to the latest version, as the historical data suggests a pattern of exploitable weaknesses.
Key Concerns
- Low output escaping percentage (3%)
- History of High severity CVEs (2)
- History of XSS vulnerability type
- History of PHP Remote File Inclusion vulnerability type
- Recent vulnerability date (2026-02-05)
GMap Targeting – Simple Targeting Inside Google Maps Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
GMap Targeting <= 1.1.7 - Unauthenticated Stored Cross-Site Scripting
Google Map Targeting <= 1.1.6 - Authenticated (Subscriber+) Local File Inclusion
GMap Targeting – Simple Targeting Inside Google Maps Release Timeline
GMap Targeting – Simple Targeting Inside Google Maps Code Analysis
Output Escaping
GMap Targeting – Simple Targeting Inside Google Maps Attack Surface
AJAX Handlers 1
WordPress Hooks 6
Maintenance & Trust
GMap Targeting – Simple Targeting Inside Google Maps Maintenance & Trust
Maintenance Signals
Community Trust
GMap Targeting – Simple Targeting Inside Google Maps Alternatives
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Sitemap by BestWebSoft – WordPress XML Site Map Page Generator Plugin
google-sitemap-plugin
Generate and add XML sitemap to WordPress website. Help search engines index your blog.
Contact Page
contact-page
Easily create a contact page with relevant address information, Google Maps, your latest tweets and links to relevant social media profiles.
Alpha Google Map For Elementor
alpha-google-map-for-elementor
Alpha Google Map For Elementor offers premium Google Map features for WordPress, enhancing your site with advanced map functionalities.
WC – APG City
wc-apg-city
Add to WooCommerce an automatic city name generated from postcode.
GMap Targeting – Simple Targeting Inside Google Maps Developer Profile
12 plugins · 188K total installs
How We Detect GMap Targeting – Simple Targeting Inside Google Maps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gmap-targeting/css/admin.css/wp-content/plugins/gmap-targeting/css/shortcodes.css/wp-content/plugins/gmap-targeting/js/admin.js/wp-content/plugins/gmap-targeting/js/editor.js/wp-content/plugins/gmap-targeting/js/wp38/editor.js/wp-content/plugins/gmap-targeting/js/pn_popup/pn_advanced_wp_popup.js/wp-content/plugins/gmap-targeting/js/pn_popup/styles.csshttps://maps.google.com/maps/api/js?sensor=falsegmap-targeting/style.css?ver=gmap-targeting/script.js?ver=HTML / DOM Fingerprints
gmap_targeting_icon<!-- 05-12-2025 -->gmap_targetinggmap_targeting_ajaxpn_gmt_plugin_urlpn_lang_loadinggmt_lang_insertgmt_lang_popup_titlegmt_lang_made_by+2 more[gmap_targeting]gmap_targeting