Google Map with FancyBox Popup Security & Risk Analysis

wordpress.org/plugins/google-map-with-fancybox-popup

It allows you to add a Google Map into popup. Great plugin to display your business location in a Google map or, your personal address in Google Map.

100 active installs v3.0 PHP + WP 3.4+ Updated Dec 1, 2022
fancyboxgoogle-mappopup
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Google Map with FancyBox Popup Safe to Use in 2026?

Generally Safe

Score 85/100

Google Map with FancyBox Popup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The 'google-map-with-fancybox-popup' plugin version 3.0 exhibits a generally good security posture, with no known vulnerabilities or critical taint flows. The code analysis reveals a high percentage of SQL queries using prepared statements and a reasonable number of nonce and capability checks. The limited attack surface, consisting of a single shortcode and no AJAX handlers or REST API routes without checks, further contributes to its perceived safety.

However, there are areas for concern. A significant portion of output is not properly escaped (43%), which could lead to Cross-Site Scripting (XSS) vulnerabilities if malicious data is introduced. The presence of file operations, even without direct evidence of malicious use in this static analysis, warrants caution. While the plugin has no recorded vulnerability history, this could also indicate a lack of thorough security auditing or a small user base, rather than an inherent lack of security flaws.

In conclusion, while the plugin demonstrates some good security practices and currently shows no critical vulnerabilities, the unescaped output presents a notable risk that requires attention. The absence of historical vulnerabilities should not be interpreted as definitive proof of security; ongoing vigilance and potential for improvement remain.

Key Concerns

  • Unescaped output detected (43%)
  • File operations present
Vulnerabilities
None known

Google Map with FancyBox Popup Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Google Map with FancyBox Popup Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
12 prepared
Unescaped Output
42
32 escaped
Nonce Checks
6
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
0

SQL Query Safety

92% prepared13 total queries

Output Escaping

43% escaped74 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
<gmwfb-add> (page\gmwfb-add.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Google Map with FancyBox Popup Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[google-map-fb-popup] google-map-with-fancybox-popup.php:39
WordPress Hooks 5
actionadmin_menugoogle-map-with-fancybox-popup.php:35
actionwidgets_initgoogle-map-with-fancybox-popup.php:38
actionwp_enqueue_scriptsgoogle-map-with-fancybox-popup.php:40
actionadmin_headgoogle-map-with-fancybox-popup.php:41
actionplugins_loadedgoogle-map-with-fancybox-popup.php:47
Maintenance & Trust

Google Map with FancyBox Popup Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 1, 2022
PHP min version
Downloads15K

Community Trust

Rating56/100
Number of ratings5
Active installs100
Developer Profile

Google Map with FancyBox Popup Developer Profile

gopiplus

52 plugins · 19K total installs

76
trust score
Avg Security Score
83/100
Avg Patch Time
70 days
View full developer profile
Detection Fingerprints

How We Detect Google Map with FancyBox Popup

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/google-map-with-fancybox-popup/js/gmwfb-map-script.js/wp-content/plugins/google-map-with-fancybox-popup/css/gmwfb-map-style.css
Script Paths
https://maps.googleapis.com/maps/api/js?key=AIzaSyA2l4SJrBt-_rrExNUyno16XvbW6gQNBug

HTML / DOM Fingerprints

CSS Classes
gmwfb-google-map
Data Attributes
gmwfb_google_map_latgmwfb_google_map_lnggmwfb_google_map_addressgmwfb_google_map_zoomgmwfb_google_map_marker_icongmwfb_google_map_popup_content+1 more
JS Globals
gmwfb_map_data
Shortcode Output
[google-map-fb-popup]
FAQ

Frequently Asked Questions about Google Map with FancyBox Popup