Interactive Regional Map of Africa Security & Risk Analysis

wordpress.org/plugins/interactive-map-of-africa

Interactive regional map of Africa WordPress plugin with an easy to use admin panel interface.

30 active installs v1.0 PHP + WP 3.4+ Updated Apr 27, 2025
africa-mapafrica-mapsafrican-mapclickable-mapsinteractive-maps
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEJun 5, 2025
Safety Verdict

Is Interactive Regional Map of Africa Safe to Use in 2026?

Mostly Safe

Score 78/100

Interactive Regional Map of Africa is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Jun 5, 2025Updated 11mo ago
Risk Assessment

The "interactive-map-of-africa" v1.0 plugin exhibits a mixed security posture. While it demonstrates good practices by avoiding dangerous functions, performing all SQL queries with prepared statements, and having no file operations or external HTTP requests, significant concerns arise from output escaping and its vulnerability history. The complete lack of output escaping (0% properly escaped) represents a critical risk for Cross-Site Scripting (XSS) vulnerabilities, as any data rendered to the user interface could be manipulated. The taint analysis also indicates a potential issue with unsanitized paths, although it's not classified as a critical or high severity vulnerability.

The plugin's vulnerability history is a major red flag, with one known medium severity CVE that is currently unpatched. The common vulnerability type being Cross-Site Request Forgery (CSRF) suggests that even if code logic is sound, user actions might not be adequately protected. The recent nature of the last vulnerability (2025-06-05) indicates ongoing security challenges. Despite having a small attack surface and no immediately obvious unprotected entry points, the lack of proper output escaping and the unpatched CVE significantly undermine its overall security. Developers should prioritize addressing the unescaped output and the existing CVE to improve the plugin's security.

Key Concerns

  • Unescaped output (0% properly escaped)
  • Unpatched CVE (medium severity)
  • Taint analysis: unsanitized paths
  • No nonce checks
  • No capability checks
Vulnerabilities
1

Interactive Regional Map of Africa Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-49449medium · 4.3Cross-Site Request Forgery (CSRF)

Interactive Regional Map of Africa <= 1.0 - Cross-Site Request Forgery

Jun 5, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Interactive Regional Map of Africa Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
44
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE1.0

Output Escaping

0% escaped44 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
__construct (afr-map.php:13)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Interactive Regional Map of Africa Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[afr_map] afr-map.php:20
WordPress Hooks 4
actionadmin_menuafr-map.php:16
actionadmin_footerafr-map.php:17
actionwp_footerafr-map.php:18
actionadmin_enqueue_scriptsafr-map.php:19
Maintenance & Trust

Interactive Regional Map of Africa Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 27, 2025
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs30
Developer Profile

Interactive Regional Map of Africa Developer Profile

WP Map Plugins

7 plugins · 2K total installs

77
trust score
Avg Security Score
84/100
Avg Patch Time
81 days
View full developer profile
Detection Fingerprints

How We Detect Interactive Regional Map of Africa

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/interactive-map-of-africa/map-style.css/wp-content/plugins/interactive-map-of-africa/map-interact.js/wp-content/plugins/interactive-map-of-africa/style.css/wp-content/plugins/interactive-map-of-africa/tinyeditor.css/wp-content/plugins/interactive-map-of-africa/js/tinymce.min.js/wp-content/plugins/interactive-map-of-africa/js/scripts.js
Script Paths
/wp-content/plugins/interactive-map-of-africa/map-interact.js/wp-content/plugins/interactive-map-of-africa/js/tinymce.min.js/wp-content/plugins/interactive-map-of-africa/js/scripts.js
Version Parameters
interactive-map-of-africa/map-style.css?ver=interactive-map-of-africa/map-interact.js?ver=interactive-map-of-africa/style.css?ver=interactive-map-of-africa/tinyeditor.css?ver=interactive-map-of-africa/js/tinymce.min.js?ver=interactive-map-of-africa/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
afr_map_admin_css
Data Attributes
id="tipafr"id="wpurl"
JS Globals
var AFRMAP_VERSION =var AFRMAP_DIR =var AFRMAP_URL =var afr_map_options =
Shortcode Output
<div class="afr_map_admin_css">
FAQ

Frequently Asked Questions about Interactive Regional Map of Africa