
Maps Widget for Google Maps Security & Risk Analysis
wordpress.org/plugins/google-maps-widgetAre your Google Maps slow? Try Map Widget for Google Maps. You'll have a fast Google Maps widget with a thumbnail & lightbox map in minutes!
Is Maps Widget for Google Maps Safe to Use in 2026?
Generally Safe
Score 99/100Maps Widget for Google Maps has a strong security track record. Known vulnerabilities have been patched promptly.
The google-maps-widget plugin version 4.27 exhibits a mixed security posture. On the positive side, it demonstrates good practices by having no SQL queries that are not prepared, no file operations, and no identified critical or high severity taint flows. The presence of nonce and capability checks on its AJAX handlers, although limited, is also a good sign. However, concerns arise from the output escaping, where 74% is properly escaped, leaving a significant portion (26%) potentially vulnerable to Cross-Site Scripting (XSS) if not handled with care. The plugin also makes 5 external HTTP requests, which could be a vector for supply chain attacks if the external services are compromised.
The vulnerability history reveals two medium severity CVEs, both related to Cross-Site Scripting (XSS) and Cross-Site Request Forgery (CSRF). The fact that there are no currently unpatched vulnerabilities is reassuring, but the recurring nature of XSS and CSRF suggests that input sanitization and output encoding might require more robust implementation. The last vulnerability was in April 2023, indicating that while the plugin has been updated, past issues warrant continued vigilance. Overall, the plugin has strengths in its prepared SQL and lack of critical taint issues, but the output escaping and past vulnerability types highlight areas for improvement.
Key Concerns
- Potential unescaped output
- Bundled library (Select2) - potential for outdated version
- Medium severity CVE history (2 instances)
Maps Widget for Google Maps Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Maps Widget for Google Maps <= 4.24 - Authenticated (Administrator+) Stored Cross-Site Scripting
Maps Widget for Google Maps <= 4.23 - Cross-Site Request Forgery via dismiss_notice
Maps Widget for Google Maps Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Maps Widget for Google Maps Attack Surface
AJAX Handlers 3
WordPress Hooks 21
Maintenance & Trust
Maps Widget for Google Maps Maintenance & Trust
Maintenance Signals
Community Trust
Maps Widget for Google Maps Alternatives
Simple Google Maps Widget
simple-google-maps-widget
A simple yet cool and intuitive Google maps widget for your website
WP Go Maps (formerly WP Google Maps)
wp-google-maps
The easiest to use Google maps plugin! Create a custom Google map, map block, store locator or map widget with high quality markers containing categor …
iframe
iframe
[iframe src="http://www.youtube.com/embed/7_nAZQt9qu0" width="100%" height="500"] shortcode
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
WP Store Locator
wp-store-locator
An easy to use location management system that enables users to search for nearby physical stores.
Maps Widget for Google Maps Developer Profile
28 plugins · 3.5M total installs
How We Detect Maps Widget for Google Maps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/google-maps-widget/js/frontend.js/wp-content/plugins/google-maps-widget/css/frontend.css/wp-content/plugins/google-maps-widget/js/frontend.js/wp-content/plugins/google-maps-widget/js/admin.js/wp-content/plugins/google-maps-widget/js/admin.jsgoogle-maps-widget/js/frontend.js?ver=google-maps-widget/css/frontend.css?ver=google-maps-widget/js/admin.js?ver=HTML / DOM Fingerprints
gmw-map-wrappergmw-map-canvas<!-- START GMW MAP WIDGET --><!-- END GMW MAP WIDGET --><!-- Maps Widget for Google Maps Settings --><!-- END Maps Widget for Google Maps Settings -->data-gmw-optionsgmw_options/wp-json/gmw/v1/settings[google-maps-widget