Interactive Regional Map of Florida Security & Risk Analysis

wordpress.org/plugins/interactive-map-of-florida

Interactive regional map of Florida WordPress plugin with an easy to use admin panel interface.

20 active installs v1.0 PHP + WP 3.4+ Updated Apr 27, 2025
clickable-mapsflorida-mapflorida-map-templateflorida-mapsinteractive-maps
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEJun 5, 2025
Safety Verdict

Is Interactive Regional Map of Florida Safe to Use in 2026?

Mostly Safe

Score 78/100

Interactive Regional Map of Florida is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Jun 5, 2025Updated 11mo ago
Risk Assessment

The "interactive-map-of-florida" plugin v1.0 presents a mixed security posture. On the positive side, the plugin has a very limited attack surface with only one shortcode entry point, and importantly, no AJAX handlers or REST API routes that are unprotected. All SQL queries are properly prepared, and there are no file operations or external HTTP requests, which are excellent security practices. However, a significant concern is the complete lack of output escaping across all 59 detected outputs. This means any data rendered by the plugin, if it originates from an untrusted source or contains malicious characters, could lead to Cross-Site Scripting (XSS) vulnerabilities. The taint analysis also revealed two flows with unsanitized paths, although they are not categorized as critical or high severity, this indicates potential weaknesses in how data is handled that could be exploited in conjunction with other vulnerabilities.

The plugin's vulnerability history is a major red flag. It has a known CVE that is currently unpatched, classified as medium severity. This is particularly concerning given the recent date of this vulnerability (June 2025). The common vulnerability type being "Missing Authorization" in the past suggests a pattern of insecure handling of user roles and permissions, which, when combined with unescaped output, could create significant security risks. While the current version avoids some common pitfalls like unprotected AJAX/REST endpoints, the persistent issue with unpatched vulnerabilities and the pervasive lack of output escaping make this plugin a significant risk, especially if the past "Missing Authorization" vulnerabilities are related to its current functionality or could be triggered via its shortcode.

In conclusion, the plugin demonstrates good practices in limiting its attack surface and secure database interaction. However, the critical absence of output escaping and a recent, unpatched medium-severity vulnerability with a history of authorization issues create substantial security concerns. The potential for XSS due to unescaped output, coupled with past authorization flaws and the current unpatched CVE, necessitates careful consideration and remediation before widespread deployment.

Key Concerns

  • Unpatched CVE (medium severity)
  • All outputs unescaped
  • Taint flows with unsanitized paths
  • No nonce checks
  • No capability checks
  • Bundled outdated library (TinyMCE v1.0)
Vulnerabilities
1

Interactive Regional Map of Florida Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-49441medium · 5.3Missing Authorization

Interactive Regional Map of Florida <= 1.0 - Missing Authorization

Jun 5, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Interactive Regional Map of Florida Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
59
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE1.0

Output Escaping

0% escaped59 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
__construct (flr-map.php:13)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Interactive Regional Map of Florida Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[flr_map] flr-map.php:20
WordPress Hooks 4
actionadmin_menuflr-map.php:16
actionadmin_footerflr-map.php:17
actionwp_footerflr-map.php:18
actionadmin_enqueue_scriptsflr-map.php:19
Maintenance & Trust

Interactive Regional Map of Florida Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 27, 2025
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Interactive Regional Map of Florida Developer Profile

WP Map Plugins

7 plugins · 2K total installs

77
trust score
Avg Security Score
84/100
Avg Patch Time
81 days
View full developer profile
Detection Fingerprints

How We Detect Interactive Regional Map of Florida

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/interactive-map-of-florida/map-style.css/wp-content/plugins/interactive-map-of-florida/map-interact.js/wp-content/plugins/interactive-map-of-florida/style.css/wp-content/plugins/interactive-map-of-florida/tinyeditor.css/wp-content/plugins/interactive-map-of-florida/js/tinymce.min.js/wp-content/plugins/interactive-map-of-florida/js/scripts.js
Script Paths
/wp-content/plugins/interactive-map-of-florida/map-interact.js/wp-content/plugins/interactive-map-of-florida/js/tinymce.min.js/wp-content/plugins/interactive-map-of-florida/js/scripts.js
Version Parameters
interactive-map-of-florida/map-style.css?ver=1.0interactive-map-of-florida/map-interact.js?ver=1.0interactive-map-of-florida/style.css?ver=1.0interactive-map-of-florida/map-style.css?ver=1.0interactive-map-of-florida/tinyeditor.css?ver=1.0interactive-map-of-florida/map-interact.js?ver=1.0interactive-map-of-florida/js/tinymce.min.js?ver=1.0interactive-map-of-florida/js/scripts.js?ver=1.0

HTML / DOM Fingerprints

CSS Classes
flr-map-container
Data Attributes
data-region-iddata-region-colordata-region-urldata-region-target
JS Globals
flr_map_options
Shortcode Output
<div id="flr-map-container">
FAQ

Frequently Asked Questions about Interactive Regional Map of Florida