[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fFtNkxQf8-mCLg7B3rHw54G0BCU11b3XIjT8g57bNjks":3,"$fkmEU3nH2_Hj8pffc5AxRQkwVc8L3kOXnZkWKAvd8r78":306,"$fuBD_pSjvANLGZlMInthxwMWnrd3xx3NE2BRS0_gGWXg":310},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":11,"num_ratings":13,"last_updated":14,"tested_up_to":15,"requires_at_least":16,"requires_php":17,"tags":18,"homepage":24,"download_link":25,"security_score":26,"vuln_count":27,"unpatched_count":27,"last_vuln_date":28,"fetched_at":29,"discovery_status":30,"vulnerabilities":31,"developer":49,"crawl_stats":37,"alternatives":53,"analysis":142,"fingerprints":284},"gps-plotter","Gps Plotter","5.4.0","Steve Curtis","https:\u002F\u002Fprofiles.wordpress.org\u002Fchilifide\u002F","\u003Cp>\u003Ca href=\"https:\u002F\u002Fwww.stpetedesign.com\u002Fproduct\u002Fgps-plotter-bootleg\u002F\" rel=\"nofollow ugc\">GPS Plotter by St. Pete Design\u003C\u002Fa> allows you to track Android phones in real time. GPS Plotter displays a map on your website with your present location using Openstreet Maps or Google Maps. We recommend that you start with Openstreet Maps unless you have experience with Google Maps API.\u003C\u002Fp>\n\u003Cp>GPS Plotter was forked from a plugin called GPS Tracker by Nick Fox. Nick stopped development on GPS Tracker so we picked up where he left off. You can watch the cell phones being tracked using Openstreet maps and Google maps and you can store and reload routes easily for later viewing. The plugin is fully responsive and it will display properly on any device such as a cell phone, tablet or desktop computer.\u003C\u002Fp>\n\u003Cp>You can download the app from the Android store then you enter your username and the URL that you have installed the GPS Plotter plugin on. Now you are ready to click “Tracking On” to start sending GPS tracking information to that URL.\u003C\u002Fp>\n\u003Cp>Then you can go to that site on either your computer or mobile device and check out the GPS information you are sending for yourself.\u003C\u002Fp>\n\u003Cp>I hope you find this plugin useful. If you find any bugs, please email us so we can address any issues that come up immediately.\u003C\u002Fp>\n\u003Cp>Please rate it and leave a review so we can help other developers find this software. Thanks!\u003C\u002Fp>\n","Use Google maps to track cell phones from your WordPress website in real time.",90,9964,10,"2026-04-20T03:18:00.000Z","6.9.5","4.0","",[19,20,21,22,23],"android","cell-phone","google-maps","gps","plotter","https:\u002F\u002Fwww.stpetedesign.com\u002Fgps-plotter\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgps-plotter.zip",79,1,"2023-04-21 00:00:00","2026-07-22T17:31:50.256Z","no_bundle",[32],{"id":33,"url_slug":34,"title":35,"description":36,"plugin_slug":4,"theme_slug":37,"affected_versions":38,"patched_in_version":37,"severity":39,"cvss_score":40,"cvss_vector":41,"vuln_type":42,"published_date":28,"updated_date":43,"references":44,"days_to_patch":37,"patch_diff_files":46,"patch_trac_url":37,"research_status":37,"research_verified":47,"research_rounds_completed":48,"research_plan":37,"research_summary":37,"research_vulnerable_code":37,"research_fix_diff":37,"research_exploit_outline":37,"research_model_used":37,"research_started_at":37,"research_completed_at":37,"research_error":37,"poc_status":37,"poc_video_id":37,"poc_summary":37,"poc_steps":37,"poc_tested_at":37,"poc_wp_version":37,"poc_php_version":37,"poc_playwright_script":37,"poc_exploit_code":37,"poc_has_trace":47,"poc_model_used":37,"poc_verification_depth":37},"CVE-2023-30874","gps-plotter-authenticated-administrator-stored-cross-site-scripting","GPS Plotter \u003C= 5.3.0 - Authenticated (Administrator+) Stored Cross-Site Scripting","The GPS Plotter plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in versions up to, and including, 5.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts multi-site installations and installations where unfiltered_html has been disabled.",null,"\u003C=5.3.0","medium",4.4,"CVSS:3.1\u002FAV:N\u002FAC:H\u002FPR:H\u002FUI:N\u002FS:C\u002FC:L\u002FI:L\u002FA:N","Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","2024-11-14 15:48:56",[45],"https:\u002F\u002Fwww.wordfence.com\u002Fthreat-intel\u002Fvulnerabilities\u002Fid\u002Fca449d15-b05e-4341-99b0-472a14cab8f4?source=api-prod",[],false,0,{"slug":50,"display_name":7,"profile_url":8,"plugin_count":27,"total_installs":11,"avg_security_score":26,"avg_patch_time_days":51,"trust_score":26,"computed_at":52},"chilifide",30,"2026-08-29T10:12:22.661Z",[54,74,93,112,130],{"slug":55,"name":56,"version":57,"author":58,"author_profile":59,"description":60,"short_description":61,"active_installs":62,"downloaded":63,"rating":48,"num_ratings":48,"last_updated":64,"tested_up_to":65,"requires_at_least":66,"requires_php":17,"tags":67,"homepage":71,"download_link":72,"security_score":73,"vuln_count":48,"unpatched_count":48,"last_vuln_date":37,"fetched_at":29},"wp-routes","WP-Routes Plugin","0.4","funkster","https:\u002F\u002Fprofiles.wordpress.org\u002Ffunkster\u002F","\u003Cp>WP-Routes Plugin allows you to embed routes into wordpress posts and pages. It is ideal for WordPress Blogs dedicated to cyclists, mountain bikers, runners, joggers, walkers, hikers, swimmers, canoeists, sailers, motorbikers and anyone else looking for routes, trails or tracks, on roads, paths, trails or even on water.\u003C\u002Fp>\n\u003Cp>WP-Routes\u003C\u002Fp>\n\u003Cp>\u003Ca href=\"http:\u002F\u002Fwww.gpsies.com\u002F\" rel=\"nofollow ugc\">GPSies\u003C\u002Fa> is an interactive service that lets you view, print or download routes, tracks and trails. These routes are available on-screen for those researching new tracks, printable for those who want to take a paper copy with them or downloadable to a wide variety of devices for those a little more tech savvy.\u003C\u002Fp>\n\u003Cp>Routes are searchable by an interactive map and list details such as distance, elevation, route characteristics etc. It uses the GPSies API [http:\u002F\u002Fwww.gpsies.com\u002Fapi\u002FGPSiesAPI_en.pdf] and allows you to embed GPS maps direct into your wordpress blog.\u003C\u002Fp>\n\u003Cp>Based on an original idea by Flavio Alberti [http:\u002F\u002Fflavio.alicubi.net\u002Fgpsiesembed\u002F] and further developed by \u003Ca href=\"https:\u002F\u002Fplus.google.com\u002F106960773695030875332\u002Fabout\" rel=\"nofollow ugc\">Mark Taylor\u003C\u002Fa> at \u003Ca href=\"http:\u002F\u002Fwww.bikes.org.uk\u002F\" rel=\"nofollow ugc\">Bikes.org.uk\u003C\u002Fa>.\u003C\u002Fp>\n\u003Cp>Map Features\u003C\u002Fp>\n\u003Cp>The WP-Routes plugin feature rich and fully interactive maps. Key features include;\u003C\u002Fp>\n\u003Cul>\n\u003Cli>Interactive Map\u003C\u002Fli>\n\u003Cli>Zoom In & Out\u003C\u002Fli>\n\u003Cli>Highlighted Route\u003C\u002Fli>\n\u003Cli>Route Distances in kilometers & miles\u003C\u002Fli>\n\u003Cli>Altitudes in meters & feet\u003C\u002Fli>\n\u003Cli>Dynamic Altitude Profile\u003C\u002Fli>\n\u003Cli>Altitude Range (min & max altitudes)\u003C\u002Fli>\n\u003Cli>Total Climb & Descents\u003C\u002Fli>\n\u003Cli>Printable Map\u003C\u002Fli>\n\u003Cli>Download to GPS Devices\u003C\u002Fli>\n\u003Cli>Track Types\u003C\u002Fli>\n\u003Cli>Locations (country, city, latitude, longitude)\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>One of the things that puts this GPS route finder ahead of other web services is that each route can be downloaded in a wide variety of file types, including downloads to all the leading GPS devices. This is the full range of downloadable options;\u003C\u002Fp>\n\u003Cul>\n\u003Cli>On-Screen via GPSies Website\u003C\u002Fli>\n\u003Cli>Printable Routes\u003C\u002Fli>\n\u003Cli>Google Earth .kml or .kmz file\u003C\u002Fli>\n\u003Cli>GPX Route & Trail\u003C\u002Fli>\n\u003Cli>CSV or MS Excel file\u003C\u002Fli>\n\u003Cli>PCX5 Track\u003C\u002Fli>\n\u003Cli>Garmin Course CRS & TCX\u003C\u002Fli>\n\u003Cli>OVL (ASCII)\u003C\u002Fli>\n\u003Cli>Fugawi\u003C\u002Fli>\n\u003Cli>KOMPASS Verlag\u003C\u002Fli>\n\u003Cli>GeoRSS Track\u003C\u002Fli>\n\u003Cli>OziExplorer\u003C\u002Fli>\n\u003Cli>MagicMaps IKT\u003C\u002Fli>\n\u003Cli>JSON Track\u003C\u002Fli>\n\u003Cli>PathAway\u003C\u002Fli>\n\u003Cli>Navigon RTE 5.x & 6.x\u003C\u002Fli>\n\u003Cli>Navigon Freshroute\u003C\u002Fli>\n\u003Cli>TomTom ITN\u003C\u002Fli>\n\u003Cli>Magellan Track\u003C\u002Fli>\n\u003Cli>CompeGPS Track\u003C\u002Fli>\n\u003Cli>qpeGPS Track\u003C\u002Fli>\n\u003Cli>Garmin Logbook\u003C\u002Fli>\n\u003C\u002Ful>\n","Add Cycle Routes, Mountain Bike Trails, Running Tracks, Walking Routes and much more to your posts and pages.",100,8710,"2012-11-28T21:04:00.000Z","3.4.2","2.5",[68,69,21,22,70],"cycling","cycling-routes","gpsies","http:\u002F\u002Fwww.bikes.org.uk\u002Froute-finder\u002Fwp-routes-plugin\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fwp-routes.zip",85,{"slug":75,"name":76,"version":77,"author":78,"author_profile":79,"description":80,"short_description":81,"active_installs":82,"downloaded":83,"rating":62,"num_ratings":84,"last_updated":85,"tested_up_to":86,"requires_at_least":16,"requires_php":17,"tags":87,"homepage":91,"download_link":92,"security_score":73,"vuln_count":48,"unpatched_count":48,"last_vuln_date":37,"fetched_at":29},"google-maps-photo-gallery","Google Maps Photo Gallery","1.3","sysbird","https:\u002F\u002Fprofiles.wordpress.org\u002Fsysbird\u002F","\u003Cp>The shortcode for gallery on Google Maps with geotagged photos.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fbirdsite.jp\u002F2007\u002F09\u002F21\u002F20070921-hakodate\u002F\" rel=\"nofollow ugc\">Demo\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fsysbird\u002Fgooglemaps-photo-gallery\" rel=\"nofollow ugc\">GitHub\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"http:\u002F\u002Fsysbird.jp\u002Fwptips\u002Fgooglemaps-photo-gallery\u002F\" rel=\"nofollow ugc\">Description in Japanese\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Features\u003C\u002Fh4>\n\u003Cul>\n\u003Cli>The plugin displays a gallery on Google Maps with geotagged photos that has been uploaded to post.\u003C\u002Fli>\n\u003Cli>When clicked the photo on the gallery, zoom in image with lightbox.\u003C\u002Fli>\n\u003Cli>It’s compatible with responsive web design.\u003C\u002Fli>\n\u003Cli>Based on \u003Ca href=\"https:\u002F\u002Fdevelopers.google.com\u002Fmaps\u002Fdocumentation\u002Fjavascript\u002F\" rel=\"nofollow ugc\">Google Maps JavaScript API v3\u003C\u002Fa>.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"https:\u002F\u002Ffancyapps.com\u002Ffancybox\u002F3\u002F\" rel=\"nofollow ugc\">fancyBox3\u003C\u002Fa> the jQuery plugin is Licensed GPLv3 for open source use.\u003C\u002Fli>\n\u003Cli>\u003Ca href=\"http:\u002F\u002Fidangero.us\u002Fswiper\u002F\" rel=\"nofollow ugc\">Swiper\u003C\u002Fa>  the jQuery plugin is under the MIT License.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch4>Usage\u003C\u002Fh4>\n\u003Col>\n\u003Cli>Upload geotagged photos in post.\u003C\u002Fli>\n\u003Cli>Please write shortcode [googlemaps-photo-gallery] in the content.\u003C\u002Fli>\n\u003Cli>You can set center photo, zoom size and height of Google Maps as the initial display.\u003Cbr \u002F>\nexample. [googlemaps-photo-gallery center=”5″ zoom=”16″ height=”750″]\u003Cbr \u002F>\ncenter: menu order of photo(default:the last photo)\u003Cbr \u002F>\nzoom: Google Maps zooming parameter(0-18 default:15)\u003Cbr \u002F>\nheight: Google Maps height(px)(default:500)\u003C\u002Fli>\n\u003C\u002Fol>\n","The shortcode for gallery on Google Maps with geotagged photos.",70,6500,6,"2019-06-29T07:52:00.000Z","5.2.24",[88,21,22,89,90],"gallery","photo","shortcode","https:\u002F\u002Fwordpress.org\u002Fplugins\u002Fgoogle-maps-photo-gallery\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgoogle-maps-photo-gallery.zip",{"slug":94,"name":95,"version":96,"author":97,"author_profile":98,"description":99,"short_description":100,"active_installs":51,"downloaded":101,"rating":102,"num_ratings":103,"last_updated":104,"tested_up_to":105,"requires_at_least":16,"requires_php":17,"tags":106,"homepage":110,"download_link":111,"security_score":73,"vuln_count":48,"unpatched_count":48,"last_vuln_date":37,"fetched_at":29},"gps-tracker","Gps Tracker","1.0.4","nicolasfox","https:\u002F\u002Fprofiles.wordpress.org\u002Fnicolasfox\u002F","\u003Cp>This is the first and only WordPress plugin that allows you to track Android cell phones in real time. You can watch the cell phones being tracked using google maps or OpenStreetView maps and you can store and reload routes easily for later viewing. The plugin is fully responsive and this means that it will display properly on any device such as a cell phone, tablet or desktop computer.\u003C\u002Fp>\n\u003Cp>View a working sample of the plugin here:\u003C\u002Fp>\n\u003Cp>https:\u002F\u002Fwww.websmithing.com\u002Fgps-tracker-for-wordpress\u002F\u003C\u002Fp>\n\u003Cp>Check out our new help forum here:\u003C\u002Fp>\n\u003Cp>https:\u002F\u002Fwww.websmithing.com\u002Fforums\u002F\u003C\u002Fp>\n\u003Cp>I hope you find this plugin useful, please rate it and leave a review. Thanks!\u003C\u002Fp>\n","Track Android cell phones in real time and store routes for later viewing.",12386,66,9,"2016-07-14T19:00:00.000Z","4.5.33",[19,107,22,108,109],"cell","phone","tracker","https:\u002F\u002Fwww.websmithing.com\u002Fgps-tracker","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgps-tracker.1.0.4.zip",{"slug":113,"name":114,"version":115,"author":116,"author_profile":117,"description":118,"short_description":119,"active_installs":13,"downloaded":120,"rating":48,"num_ratings":48,"last_updated":121,"tested_up_to":15,"requires_at_least":122,"requires_php":123,"tags":124,"homepage":128,"download_link":129,"security_score":62,"vuln_count":48,"unpatched_count":48,"last_vuln_date":37,"fetched_at":29},"gellum-delivery-calculator","Gellum Delivery Calculator for WooCommerce","1.1.3","Gellum.com","https:\u002F\u002Fprofiles.wordpress.org\u002Fgellum\u002F","\u003Cp>\u003Cspan class=\"embed-youtube\" style=\"text-align:center; display: block;\">\u003Ciframe loading=\"lazy\" class=\"youtube-player\" width=\"750\" height=\"422\" src=\"https:\u002F\u002Fwww.youtube.com\u002Fembed\u002FRXEAB7D3Z5I?version=3&rel=1&showsearch=0&showinfo=1&iv_load_policy=1&fs=1&hl=en-US&autohide=2&wmode=transparent\" allowfullscreen=\"true\" style=\"border:0;\" sandbox=\"allow-scripts allow-same-origin allow-popups allow-presentation allow-popups-to-escape-sandbox\">\u003C\u002Fiframe>\u003C\u002Fspan>\u003C\u002Fp>\n\u003Ch4>Calculate Shipping Costs by GPS Distance in WooCommerce with Interactive Map\u003C\u002Fh4>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgellum.com\u002Fopensource\" rel=\"nofollow ugc\">Gellum\u003C\u002Fa> Delivery Calculator transform your WooCommerce store’s local delivery experience. This plugin offers a robust and user-friendly way to calculate shipping costs based on the \u003Cstrong>precise GPS distance\u003C\u002Fstrong> from your store to the customer’s location. It goes beyond simple calculations by integrating an \u003Cstrong>interactive Google Map\u003C\u002Fstrong> directly into your cart or checkout process. Customers can easily pinpoint their exact delivery location on the map, or allow their browser to attempt \u003Cstrong>automatic GPS detection\u003C\u002Fstrong> for an even quicker start. You define your operational reach by drawing or uploading a \u003Cstrong>GeoJSON boundary\u003C\u002Fstrong>, ensuring that rates are only offered within your designated service area. The plugin visually displays this area on the map, providing clear feedback to the customer. The standout feature is the integration of \u003Cstrong>Google Maps Reverse Geocoding\u003C\u002Fstrong>. When a customer selects or moves their pin on the map:\u003C\u002Fp>\n\u003Col>\n\u003Cli>The plugin instantly fetches detailed address information via the Google Geocoding API.\u003C\u002Fli>\n\u003Cli>It identifies the \u003Cstrong>Google Plus Code\u003C\u002Fstrong>, \u003Cstrong>City\u003C\u002Fstrong>, \u003Cstrong>State\u002FProvince\u003C\u002Fstrong>, \u003Cstrong>Postal Code\u003C\u002Fstrong>, and \u003Cstrong>Country\u003C\u002Fstrong>.\u003Cbr \u002F>\nThis streamlines the checkout process, reduces typing errors, and enhances the overall user experience by leveraging WooCommerce’s native checkout update mechanisms. It’s particularly useful for areas where traditional street addresses might be less precise or for customers who prefer the simplicity of dropping a pin.\u003C\u002Fli>\n\u003C\u002Fol>\n\u003Cp>\u003Cstrong>Key Features:\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Interactive Google Map:\u003C\u002Fstrong> Customers visually select their delivery location.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>GPS Distance Calculation:\u003C\u002Fstrong> Uses the Haversine formula for accurate distance measurement.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>GeoJSON Delivery Area:\u003C\u002Fstrong> Define precise service zones using GeoJSON (Polygon\u002FMultiPolygon support) and visually display them.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Reverse Geocoding:\u003C\u002Fstrong> Fetches Plus Codes, City, State, Postcode, and Country from a map point.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Automatic Address Field Updates:\u003C\u002Fstrong> Populates WooCommerce Billing\u002FShipping fields (Address 1, City, State, Postcode, Country) in real-time.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Initial GPS Auto-Detection:\u003C\u002Fstrong> Attempts to find the customer’s current location via browser Geolocation API.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Configurable Rate Structure:\u003C\u002Fstrong> Set a base fee, define a maximum distance for that base fee, and add a per-kilometer cost for distances beyond that.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Free Shipping Threshold:\u003C\u002Fstrong> Offer free delivery for orders above a certain subtotal.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Order Details Storage:\u003C\u002Fstrong> Saves the customer’s selected GPS coordinates (Latitude & Longitude) with each order for your records.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Admin Order View:\u003C\u002Fstrong> Displays the customer’s GPS coordinates and a link to Google Maps directly on the order details page in the WordPress admin.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>HPOS Compatible:\u003C\u002Fstrong> Works seamlessly with WooCommerce’s High-Performance Order Storage.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Shortcode Support:\u003C\u002Fstrong> Easily place the map anywhere using the \u003Ccode>[gellumdcw_map]\u003C\u002Fcode> shortcode.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Server-Side Validation:\u003C\u002Fstrong> Includes checks during checkout to ensure the final delivery location is still within the valid GeoJSON area.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Independent Configuration:\u003C\u002Fstrong> Each subsite within your Multisite network can have its own unique Gellum Delivery Calculator settings. This includes distinct Google Maps API Keys, store locations (latitude and longitude), GeoJSON delivery areas, and pricing structures.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Separate Data Handling:\u003C\u002Fstrong> Customer sessions, cart data, and order details (including GPS coordinates saved with each order) are managed independently for each subsite, ensuring no data conflicts across your network.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Seamless Integration:\u003C\u002Fstrong> The plugin integrates smoothly with WooCommerce’s standard shipping methods and checkout processes across individual subsites.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>\u003Cstrong>✨ NEW Features\u003C\u002Fstrong>\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Configurable Distance Unit:\u003C\u002Fstrong> Choose to calculate distances and set rates in either Kilometers (km) or Miles (mi).\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Selectable Calculation Method:\u003C\u002Fstrong> Added a new setting in the shipping method configuration allowing administrators to choose between ‘Driving Route (Directions API)’ for high accuracy and ‘Straight Line (Bird’s-eye view)’ for a fast, free approximation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Dynamic Map Visualization:\u003C\u002Fstrong> The interactive map now dynamically displays the selected calculation method. It will show the precise turn-by-turn driving route or a new, stylized curved line instead of a simple straight line.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Email Map Snapshot:\u003C\u002Fstrong> A static map image is now automatically added to the WooCommerce order confirmation emails sent to the customer. This map clearly shows the store location (A) and the customer’s delivery location (B).\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cp>Gellum Delivery Calculator is ideal for restaurants, local shops, and any business offering delivery services within a defined geographic area, providing both operational control and customer convenience.\u003C\u002Fp>\n\u003Ch3>External Services\u003C\u002Fh3>\n\u003Cp>This plugin utilizes services from Google Maps Platform to provide accurate delivery cost calculation and location selection.\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Service:\u003C\u002Fstrong> Google Maps JavaScript API, Google Geocoding API, Static Maps API, Directions API.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Purpose:\u003C\u002Fstrong> The Maps JavaScript API is used to display an interactive map, allow customers to select their delivery location, and visualize the defined delivery area. The Geocoding API is used to translate the selected map coordinates into human-readable address components (e.g., Plus Code, City, State, Postal Code, Country) and to update WooCommerce checkout fields automatically. Maps Static API is used for display the delivery map on customer email. Directions API is used to retrieve, display, and calculate the distance between the merchant and the customer following the correct route.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Data Sent:\u003C\u002Fstrong>\n\u003Cul>\n\u003Cli>\u003Cstrong>Customer’s Location (Latitude and Longitude):\u003C\u002Fstrong> Sent from the user’s browser to Google Maps API when the map is initialized (if geolocation is allowed by the user) or when the user clicks\u002Fdrags the marker on the map. This data is used to geocode the location and calculate the distance from the store.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Google Maps API Key:\u003C\u002Fstrong> Sent with every request to Google Maps Platform services for authentication and billing.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>When Data is Sent:\u003C\u002Fstrong>\n\u003Cul>\n\u003Cli>Upon loading a page containing the \u003Ccode>[gellumdcw_map]\u003C\u002Fcode> shortcode (for map initialization and optional auto-detection).\u003C\u002Fli>\n\u003Cli>Whenever a user manually selects or drags the delivery location marker on the map.\u003C\u002Fli>\n\u003Cli>During the checkout process when the Gellum Delivery method is selected and validated.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Terms of Service:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fterms\" rel=\"nofollow ugc\">https:\u002F\u002Fpolicies.google.com\u002Fterms\u003C\u002Fa>\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Privacy Policy:\u003C\u002Fstrong> \u003Ca href=\"https:\u002F\u002Fpolicies.google.com\u002Fprivacy\" rel=\"nofollow ugc\">https:\u002F\u002Fpolicies.google.com\u002Fprivacy\u003C\u002Fa>\u003C\u002Fli>\n\u003C\u002Ful>\n","Calculates shipping costs for WooCommerce based on GPS distance with GeoJSON limited areas. Shortcode [gellumdcw_map]",1053,"2026-02-17T22:08:00.000Z","6.9","7.4",[125,21,22,126,127],"delivery","shipping-calculator","woocommerce","https:\u002F\u002Fgellum.com\u002Fopensource","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgellum-delivery-calculator.1.1.3.zip",{"slug":131,"name":132,"version":133,"author":134,"author_profile":135,"description":136,"short_description":137,"active_installs":13,"downloaded":138,"rating":48,"num_ratings":48,"last_updated":139,"tested_up_to":17,"requires_at_least":66,"requires_php":17,"tags":140,"homepage":17,"download_link":141,"security_score":73,"vuln_count":48,"unpatched_count":48,"last_vuln_date":37,"fetched_at":29},"google-maps-hyperlink","Google Maps Hyperlink","1.0","Claudio Tereso","https:\u002F\u002Fprofiles.wordpress.org\u002Fclaudiotereso\u002F","\u003Cp>Converts a shortcode with the format [gmaplink name=”description” gps=”xºxx.xxxN,xºxx.xxxW”]  to a google maps query hyperlink in the format  http:\u002F\u002Fmaps.google.com\u002Fmaps?q=[gps]+([name])\u003C\u002Fp>\n\u003Cp>the gps field can be any format that the google maps query accepts.\u003C\u002Fp>\n","Converts a shortcode with the format [gmaplink name=\"description\" gps=\"xºxx.xxxN,xºxx.xxxW\"]  to a google maps hyperlink",1992,"2019-11-11T18:12:00.000Z",[21,22],"https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fgoogle-maps-hyperlink.1.0.zip",{"attackSurface":143,"codeSignals":215,"taintFlows":271,"riskAssessment":272,"analyzedAt":283},{"hooks":144,"ajaxHandlers":186,"restRoutes":208,"shortcodes":209,"cronEvents":214,"entryPointCount":103,"unprotectedCount":48},[145,151,154,157,162,167,171,173,177,181],{"type":146,"name":147,"callback":148,"file":149,"line":150},"action","admin_menu","gpspl_admin_add_page","admin\\views\\options.php",4,{"type":146,"name":152,"callback":153,"file":149,"line":103},"admin_init","gpspl_update_extra_post_info",{"type":146,"name":152,"callback":155,"file":149,"line":156},"gpspl_plugin_admin_init",96,{"type":146,"name":158,"callback":159,"file":160,"line":161},"plugins_loaded","get_instance","gpsplotter.php",45,{"type":146,"name":163,"callback":164,"file":165,"line":166},"init","load_plugin_textdomain","public\\class-gpsplotter.php",81,{"type":146,"name":168,"callback":169,"file":165,"line":170},"wp_enqueue_scripts","register_styles",84,{"type":146,"name":168,"callback":172,"file":165,"line":73},"register_scripts",{"type":146,"name":163,"callback":174,"file":175,"line":176},"add_gpsplotter_endpoint","public\\includes\\class-gpsplotter-endpoint.php",34,{"type":146,"name":178,"callback":179,"file":175,"line":180},"template_redirect","process_gpsplotter_query",35,{"type":182,"name":183,"callback":184,"file":175,"line":185},"filter","query_vars","gpsplotter_query_vars",36,[187,193,195,198,199,201,202,206],{"action":188,"nopriv":47,"callback":189,"hasNonce":190,"hasCapCheck":47,"file":191,"line":192},"get_routes","get_gps_routes",true,"public\\includes\\class-gpsplotter-ajax.php",31,{"action":188,"nopriv":190,"callback":189,"hasNonce":190,"hasCapCheck":47,"file":191,"line":194},32,{"action":196,"nopriv":47,"callback":196,"hasNonce":190,"hasCapCheck":47,"file":191,"line":197},"get_all_geojson_routes",33,{"action":196,"nopriv":190,"callback":196,"hasNonce":190,"hasCapCheck":47,"file":191,"line":176},{"action":200,"nopriv":47,"callback":200,"hasNonce":190,"hasCapCheck":47,"file":191,"line":180},"get_geojson_route",{"action":200,"nopriv":190,"callback":200,"hasNonce":190,"hasCapCheck":47,"file":191,"line":185},{"action":203,"nopriv":47,"callback":204,"hasNonce":190,"hasCapCheck":47,"file":191,"line":205},"delete_route","delete_gps_route",37,{"action":203,"nopriv":190,"callback":204,"hasNonce":190,"hasCapCheck":47,"file":191,"line":207},38,[],[210],{"tag":211,"callback":212,"file":165,"line":213},"gps_plotter","gpsplotter_map_shortcode",88,[],{"dangerousFunctions":216,"sqlUsage":217,"outputEscaping":251,"fileOperations":48,"externalRequests":48,"nonceChecks":253,"capabilityChecks":252,"bundledLibraries":270},[],{"prepared":218,"raw":219,"locations":220},21,15,[221,225,227,229,231,233,235,237,239,241,244,245,247,248,249],{"file":222,"line":223,"context":224},"includes\\class-gpsplotter-setup.php",74,"$wpdb->get_var() with variable interpolation",{"file":222,"line":62,"context":226},"$wpdb->query() with variable interpolation",{"file":222,"line":228,"context":226},138,{"file":222,"line":230,"context":226},154,{"file":222,"line":232,"context":226},174,{"file":222,"line":234,"context":226},227,{"file":222,"line":236,"context":226},230,{"file":222,"line":238,"context":226},233,{"file":222,"line":240,"context":226},236,{"file":191,"line":242,"context":243},59,"$wpdb->get_results() with variable interpolation",{"file":191,"line":228,"context":243},{"file":246,"line":194,"context":226},"uninstall.php",{"file":246,"line":180,"context":226},{"file":246,"line":207,"context":226},{"file":246,"line":250,"context":226},41,{"escaped":252,"rawEcho":253,"locations":254},2,7,[255,258,260,262,264,266,268],{"file":149,"line":256,"context":257},65,"raw output",{"file":149,"line":259,"context":257},109,{"file":191,"line":261,"context":257},76,{"file":191,"line":263,"context":257},120,{"file":191,"line":265,"context":257},155,{"file":175,"line":267,"context":257},71,{"file":175,"line":269,"context":257},127,[],[],{"summary":273,"deductions":274},"The \"gps-plotter\" plugin v5.3.0 presents a mixed security posture. On the positive side, there are no identified critical or high severity taint flows, and the plugin utilizes a reasonable number of nonce and capability checks for its entry points. The absence of dangerous functions, file operations, and external HTTP requests further contributes to a generally sound foundation.\n\nHowever, significant concerns arise from the vulnerability history and static analysis. The presence of an unpatched medium severity CVE for Cross-Site Scripting (XSS) is a critical flaw that exposes users to significant risk. Furthermore, the static analysis reveals a substantial portion of SQL queries are not using prepared statements, potentially opening the door to SQL injection vulnerabilities. The low rate of proper output escaping (22%) also indicates a high risk of XSS attacks, as user-supplied data may be rendered directly in the browser without proper sanitization.\n\nIn conclusion, while the plugin has some good security practices, the combination of an unpatched XSS vulnerability and widespread potential for SQL injection and XSS due to unescaped output and raw SQL queries creates a concerning security risk. These issues, particularly the unpatched CVE, necessitate immediate attention.",[275,278,281],{"reason":276,"points":277},"Unpatched medium severity CVE",17,{"reason":279,"points":280},"Significant percentage of raw SQL queries",8,{"reason":282,"points":84},"Low percentage of properly escaped output","2026-03-16T21:12:04.325Z",{"wat":285,"direct":296},{"assetPaths":286,"generatorPatterns":290,"scriptPaths":291,"versionParams":293},[287,288,289],"\u002Fwp-content\u002Fplugins\u002Fgps-plotter\u002Fassets\u002Fjs\u002Fleaflet-0.7.5\u002Fleaflet.css","\u002Fwp-content\u002Fplugins\u002Fgps-plotter\u002Fassets\u002Fcss\u002Flight.css","\u002Fwp-content\u002Fplugins\u002Fgps-plotter\u002Fassets\u002Fjs\u002Fgpsplotter-map.js",[],[292,289],"\u002F\u002Fmaps.googleapis.com\u002Fmaps\u002Fapi\u002Fjs?libraries=places&key=",[294,295],"gps-plotter\u002Fassets\u002Fcss\u002Flight.css?ver=","gps-plotter\u002Fassets\u002Fjs\u002Fgpsplotter-map.js?ver=",{"cssClasses":297,"htmlComments":298,"htmlAttributes":300,"restEndpoints":301,"jsGlobals":302,"shortcodeOutput":304},[],[299],"\u003C!-- to use this plugin, add this shortcode to any page or post: [gps_plotter]  -->",[],[],[303],"gpsplotter_map",[305],"[gps_plotter]",{"error":190,"url":307,"statusCode":308,"statusMessage":309,"message":309},"http:\u002F\u002Flocalhost\u002Fapi\u002Fplugins\u002Fgps-plotter\u002Fbundle",404,"no bundle for this plugin yet",{"slug":4,"current_version":6,"total_versions":48,"versions":311},[]]