Interactive Australia Map Security & Risk Analysis

wordpress.org/plugins/interactive-australia-map

Free WordPress plugin for embedding an interactive Australia map with clickable states. Easy to install and configure.

80 active installs v3.4.8 PHP + WP 3.3+ Updated Dec 3, 2025
html5-mapinteractive-mapjavascriptmapmaps
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Interactive Australia Map Safe to Use in 2026?

Generally Safe

Score 100/100

Interactive Australia Map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "interactive-australia-map" plugin version 3.4.8 exhibits a mixed security posture. While the absence of known CVEs and the exclusive use of prepared statements for SQL queries are positive indicators, several critical concerns are present. A significant portion of the attack surface, specifically 4 out of 6 identified entry points (AJAX handlers), lack authentication checks. This opens the door for potential unauthorized actions if these handlers can be triggered by unauthenticated users. Furthermore, only 15% of output operations are properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, while not revealing critical or high-severity vulnerabilities, shows 9 out of 11 flows with unsanitized paths, which warrants further investigation and suggests potential for unexpected behavior or data manipulation. The lack of recorded vulnerabilities might suggest a lack of historical scrutiny or that previous issues have been addressed, but the current code analysis reveals significant weaknesses that require immediate attention.

Key Concerns

  • AJAX handlers without authentication
  • Low percentage of properly escaped output
  • Taint flows with unsanitized paths
  • Low number of capability checks
Vulnerabilities
None known

Interactive Australia Map Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Interactive Australia Map Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
279
50 escaped
Nonce Checks
8
Capability Checks
1
File Operations
16
External Requests
0
Bundled Libraries
0

Output Escaping

15% escaped329 total outputs
Data Flows
9 unsanitized

Data Flow Analysis

11 flows9 with unsanitized paths
<editmainconfig> (editmainconfig.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Interactive Australia Map Attack Surface

Entry Points6
Unprotected4

AJAX Handlers 4

authwp_ajax_freeaustraliahtml5map_settings_jsfreeaustraliamap.php:687
noprivwp_ajax_freeaustraliahtml5map_settings_jsfreeaustraliamap.php:688
authwp_ajax_freeaustraliahtml5map_state_infofreeaustraliamap.php:704
noprivwp_ajax_freeaustraliahtml5map_state_infofreeaustraliamap.php:705

Shortcodes 2

[freeaustraliahtml5map] freeaustraliamap.php:191
[freeaustraliamap01] freeaustraliamap.php:1451
WordPress Hooks 10
actionplugins_loadedfreeaustraliamap.php:21
actionadmin_menufreeaustraliamap.php:28
actionadmin_initfreeaustraliamap.php:151
actionwp_enqueue_scriptsfreeaustraliamap.php:182
actionadmin_footerfreeaustraliamap.php:629
actionwp_footerfreeaustraliamap.php:631
actioninitfreeaustraliamap.php:707
filterwidget_textfreeaustraliamap.php:1084
filteruser_has_capfreeaustraliamap.php:1353
actioninitfreeaustraliamap.php:1433
Maintenance & Trust

Interactive Australia Map Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs80
Developer Profile

Interactive Australia Map Developer Profile

html5maps

6 plugins · 7K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
347 days
View full developer profile
Detection Fingerprints

How We Detect Interactive Australia Map

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/interactive-australia-map/static/css/tipsy.css/wp-content/plugins/interactive-australia-map/static/css/mapadm.css/wp-content/plugins/interactive-australia-map/static/js/map_admin.js/wp-content/plugins/interactive-australia-map/static/js/map_frontend.js/wp-content/plugins/interactive-australia-map/static/js/marker.js/wp-content/plugins/interactive-australia-map/static/js/raphael.js/wp-content/plugins/interactive-australia-map/static/js/jquery.vmap.js/wp-content/plugins/interactive-australia-map/static/js/australiamap.js+2 more
Script Paths
/wp-content/plugins/interactive-australia-map/static/js/map_admin.js/wp-content/plugins/interactive-australia-map/static/js/map_frontend.js/wp-content/plugins/interactive-australia-map/static/js/marker.js/wp-content/plugins/interactive-australia-map/static/js/raphael.js/wp-content/plugins/interactive-australia-map/static/js/jquery.vmap.js/wp-content/plugins/interactive-australia-map/static/js/australiamap.js+2 more
Version Parameters
freeaustralia-html5-map-adm?ver=3.4.8australiamap?ver=3.4.8jquery.js?ver=1.12.4jquery-tipsy?ver=3.4.8

HTML / DOM Fingerprints

CSS Classes
freeaustralia-html5-mapfreeaustraliaHtml5MapBoldqannerleft-blocknav-tab-wrappernav-tabnav-tab-active
HTML Comments
Temporary workaround for tinymce bug, when it's not focusable in modal windows.When comressed_scriptes is disabled - compat3x plugin for tinymcy will be added,this will prevent bug from occurring.
Data Attributes
original-title
JS Globals
freeaustralia_html5map_plugin_get_optionsfreeaustralia_html5map_plugin_get_static_url
Shortcode Output
[freeaustraliahtml5map id=
FAQ

Frequently Asked Questions about Interactive Australia Map