
MK Google Directions Security & Risk Analysis
wordpress.org/plugins/google-distance-calculatorEnable use of Google Directions in your WordPress blog.
Is MK Google Directions Safe to Use in 2026?
Use With Caution
Score 68/100MK Google Directions has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The plugin "google-distance-calculator" v3.1.1 exhibits a mixed security posture. Static analysis reveals good practices in several areas, including the absence of dangerous functions, 100% use of prepared statements for SQL queries, and all detected outputs being properly escaped. The attack surface is also minimal, with only one shortcode and no unprotected entry points. However, a significant concern arises from the lack of nonce and capability checks across all entry points, despite the static analysis reporting zero unprotected entry points. This suggests a potential reliance on external checks or an oversight in the analysis itself.
The vulnerability history indicates a past medium-severity Cross-Site Scripting (XSS) vulnerability. While there are no currently unpatched CVEs, the existence of a past XSS issue, even if resolved, warrants attention and reinforces the need for robust input validation and output escaping, which the code analysis suggests is present in its current form.
In conclusion, while the current code demonstrates strong practices regarding SQL and output handling, the absence of nonce and capability checks on its entry points is a notable weakness. The past XSS vulnerability serves as a reminder of potential risks. A balanced view suggests this plugin is generally well-coded but has areas that could be strengthened to further mitigate risks, particularly concerning authentication and authorization at its entry points.
Key Concerns
- Missing nonce checks on entry points
- Missing capability checks on entry points
- Past medium severity XSS vulnerability
MK Google Directions Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
MK Google Directions <= 3.1.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
MK Google Directions <= 3.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
MK Google Directions Release Timeline
MK Google Directions Code Analysis
Output Escaping
MK Google Directions Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
MK Google Directions Maintenance & Trust
Maintenance Signals
Community Trust
MK Google Directions Alternatives
No alternatives data available yet.
MK Google Directions Developer Profile
3 plugins · 250 total installs
How We Detect MK Google Directions
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/google-distance-calculator/css/mkgd-styles.css/wp-content/plugins/google-distance-calculator/js/mkgd.jsgoogle-distance-calculator/css/mkgd-styles.css?ver=google-distance-calculator/js/mkgd.js?ver=HTML / DOM Fingerprints
mkgd-wrapmkg-headermkgd-bodymkgdMapmkgdDirectionsid="txtSource-id="txtDestination-id="dvMap-id="dvPanel-directionsDisplay<div class="mkgd-wrap"><div class="mkg-header"><div class="mkgd-body"><div class="mkgdMap" id="dvMap-" style="width: