
indomap Security & Risk Analysis
wordpress.org/plugins/indomapjQuery plugin to create google maps with advanced features (overlays, clusters, callbacks, events...)
Is indomap Safe to Use in 2026?
Generally Safe
Score 85/100indomap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'indomap' plugin v1.0.1 exhibits a generally good security posture based on the provided static analysis. The absence of direct SQL queries, external HTTP requests, file operations, and dangerous function usage are positive indicators. The plugin also has no known vulnerabilities, including no recorded CVEs, which suggests a history of stable and secure development. The limited attack surface, with only one shortcode and no unprotected AJAX handlers or REST API routes, further contributes to its perceived security. However, a significant concern arises from the output escaping. With 100% of outputs not being properly escaped, this presents a clear risk of Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is rendered directly within the shortcode's output. While the plugin currently has no logged issues and a small attack surface, the lack of output sanitization is a critical oversight that needs immediate attention to prevent potential security breaches.
Key Concerns
- Unescaped output detected
indomap Security Vulnerabilities
indomap Release Timeline
indomap Code Analysis
Output Escaping
indomap Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
indomap Maintenance & Trust
Maintenance Signals
Community Trust
indomap Alternatives
Posts in Map
posts-in-map
Add short code [gmap] to insert in post a google map with advanced features and place geolocalized post in this map
Enable jQuery Migrate Helper
enable-jquery-migrate-helper
Get information about calls to deprecated jQuery features in plugins or themes.
jQuery Updater
jquery-updater
This plugin updates jQuery to the latest stable version on your website.
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)
leaflet-maps-marker
The most comprehensive & user-friendly mapping solution for WordPress
Use Google Libraries
use-google-libraries
Allows your site to use common javascript libraries from Google's AJAX Libraries CDN, rather than from WordPress's own copies.
indomap Developer Profile
1 plugin · 10 total installs
How We Detect indomap
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/indomap/gmap3.min.jshttp://maps.google.com/maps/api/js?sensor=false/wp-content/plugins/indomap/gmap3.min.jsHTML / DOM Fingerprints
gmap3Indo_MAP_addressparent_Indo_MAP_address<!-- #custom_setting_for_pages -->data-addressdata-widthdata-datadata-zoomdata-navigationdata-scroll+1 moregoogle[indo address="[indo address=[indo