
Instant Locations Security & Risk Analysis
wordpress.org/plugins/instant-locationsInstant & Auto populate location data with the power of Google Maps API.
Is Instant Locations Safe to Use in 2026?
Use With Caution
Score 63/100Instant Locations has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'instant-locations' plugin v1.0 exhibits a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and implementing at least one nonce and capability check, several concerning signals are present. The static analysis reveals that a significant portion of output (83%) is not properly escaped, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities. This is further supported by the taint analysis, which identified two flows with unsanitized paths, although they were not classified as critical or high severity. The vulnerability history is a significant concern, with one unpatched medium severity CVE related to XSS. The recent nature of this vulnerability (2025-09-05) suggests a recurring pattern of input sanitization issues. In conclusion, while the plugin has some positive security attributes, the high rate of unescaped output and the presence of an unpatched XSS vulnerability necessitate careful consideration and remediation.
Key Concerns
- Unpatched Medium Severity CVE (XSS)
- High percentage of unescaped output (83%)
- Taint analysis found unsanitized paths (2)
Instant Locations Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Instant Locations <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Instant Locations Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Instant Locations Attack Surface
WordPress Hooks 9
Maintenance & Trust
Instant Locations Maintenance & Trust
Maintenance Signals
Community Trust
Instant Locations Alternatives
Geolocate My Posts
geolocate-my-posts
A Wordpress plugin that tags the location of your posts using the Google Maps API.
Store Locator for WordPress Posts
wp-post-store-locator
This is a wordpress store locator plugin for posts. We can setup stores for individual posts/products.
VK All in One Expansion Unit
vk-all-in-one-expansion-unit
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Sitemap by BestWebSoft – WordPress XML Site Map Page Generator Plugin
google-sitemap-plugin
Generate and add XML sitemap to WordPress website. Help search engines index your blog.
Saitama Addon Pack
cc-addon-pack
This plug-in is an integrated plug-in with a variety of features that make it powerful your web site.
Instant Locations Developer Profile
2 plugins · 20 total installs
How We Detect Instant Locations
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/instant-locations/assets/css/instant-locations.css/wp-content/plugins/instant-locations/assets/js/instant-locations.jshttps://maps.googleapis.com/maps/api/js?libraries=placesinstant-locations/assets/css/instant-locations.css?ver=instant-locations/assets/js/instant-locations.js?ver=https://maps.googleapis.com/maps/api/js?libraries=places&key=https://maps.googleapis.com/maps/api/js?libraries=placesHTML / DOM Fingerprints
form-grouprowform-labelcolumndashicons-location-altid="form-group-address"id="address"name="location[address]"id="country"name="location[country]"id="administrative_area_level_1"+21 moregeo_config