Interactive US Map – Create Clickable & Customizable U.S. Maps Security & Risk Analysis

wordpress.org/plugins/interactive-map-of-the-us-regions

Create engaging Interactive United States Maps in WordPress for free. It's easy to install, simple, and highly customizable.

300 active installs v3.4.8 PHP 5.3.3+ WP 3.3+ Updated Dec 3, 2025
clickable-mapsinteractive-mapinteractive-mapsus-mapusa-map
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Interactive US Map – Create Clickable & Customizable U.S. Maps Safe to Use in 2026?

Generally Safe

Score 100/100

Interactive US Map – Create Clickable & Customizable U.S. Maps has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "interactive-map-of-the-us-regions" plugin, version 3.4.8, presents a moderate security risk primarily due to its unprotected entry points. While the plugin demonstrates good practices in other areas, such as the absence of known vulnerabilities and the use of prepared statements for SQL queries, the presence of four AJAX handlers without authentication checks is a significant concern. This opens the door for potential unauthorized actions or information disclosure if these handlers can be triggered by unauthenticated users.

The static analysis also reveals a concerning number of unsanitized path flows (9 out of 11). Although no critical or high severity taint flows were identified, this indicates a potential weakness that could be exploited if a malicious actor can influence these paths, possibly leading to directory traversal or file inclusion vulnerabilities. The low percentage of properly escaped output (15%) further exacerbates this risk, as it suggests that data processed by the plugin might be rendered directly in the browser without sufficient sanitization, leading to cross-site scripting (XSS) vulnerabilities.

Given the clean vulnerability history, it's possible that the current version has mitigated past issues. However, the combination of unprotected AJAX handlers, unsanitized path flows, and poor output escaping creates a situation where attackers could potentially find and exploit vulnerabilities, even without prior known issues. While the use of nonces and capability checks in some areas is positive, the unprotected entry points and output escaping issues necessitate a cautious approach.

Key Concerns

  • Unprotected AJAX handlers
  • Unsanitized path flows
  • Low output escaping percentage
Vulnerabilities
None known

Interactive US Map – Create Clickable & Customizable U.S. Maps Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Interactive US Map – Create Clickable & Customizable U.S. Maps Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
279
50 escaped
Nonce Checks
8
Capability Checks
1
File Operations
16
External Requests
0
Bundled Libraries
0

Output Escaping

15% escaped329 total outputs
Data Flows
9 unsanitized

Data Flow Analysis

11 flows9 with unsanitized paths
<editmainconfig> (editmainconfig.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Interactive US Map – Create Clickable & Customizable U.S. Maps Attack Surface

Entry Points6
Unprotected4

AJAX Handlers 4

authwp_ajax_freeusregionshtml5map_settings_jsusahtmlmap.php:687
noprivwp_ajax_freeusregionshtml5map_settings_jsusahtmlmap.php:688
authwp_ajax_freeusregionshtml5map_state_infousahtmlmap.php:704
noprivwp_ajax_freeusregionshtml5map_state_infousahtmlmap.php:705

Shortcodes 2

[freeusregionshtml5map] usahtmlmap.php:191
[freeusregionmap01] usahtmlmap.php:1452
WordPress Hooks 10
actionplugins_loadedusahtmlmap.php:21
actionadmin_menuusahtmlmap.php:28
actionadmin_initusahtmlmap.php:151
actionwp_enqueue_scriptsusahtmlmap.php:182
actionadmin_footerusahtmlmap.php:629
actionwp_footerusahtmlmap.php:631
actioninitusahtmlmap.php:707
filterwidget_textusahtmlmap.php:1084
filteruser_has_capusahtmlmap.php:1353
actioninitusahtmlmap.php:1434
Maintenance & Trust

Interactive US Map – Create Clickable & Customizable U.S. Maps Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version5.3.3
Downloads30K

Community Trust

Rating100/100
Number of ratings5
Active installs300
Developer Profile

Interactive US Map – Create Clickable & Customizable U.S. Maps Developer Profile

html5maps

6 plugins · 7K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
347 days
View full developer profile
Detection Fingerprints

How We Detect Interactive US Map – Create Clickable & Customizable U.S. Maps

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/interactive-map-of-the-us-regions/static/css/tipsy.css/wp-content/plugins/interactive-map-of-the-us-regions/static/css/mapadm.css/wp-content/plugins/interactive-map-of-the-us-regions/static/js/maps.js/wp-content/plugins/interactive-map-of-the-us-regions/static/js/maps.mapview.js/wp-content/plugins/interactive-map-of-the-us-regions/static/js/maps.mapedit.js/wp-content/plugins/interactive-map-of-the-us-regions/static/js/maps.tools.js/wp-content/plugins/interactive-map-of-the-us-regions/static/js/maps.settings.js/wp-content/plugins/interactive-map-of-the-us-regions/static/js/maps.tools.js+12 more
Script Paths
/wp-content/plugins/interactive-map-of-the-us-regions/static/js/maps.js/wp-content/plugins/interactive-map-of-the-us-regions/static/js/maps.mapview.js/wp-content/plugins/interactive-map-of-the-us-regions/static/js/maps.mapedit.js/wp-content/plugins/interactive-map-of-the-us-regions/static/js/maps.tools.js/wp-content/plugins/interactive-map-of-the-us-regions/static/js/maps.settings.js
Version Parameters
/static/css/mapadm.css?ver=3.4.8

HTML / DOM Fingerprints

CSS Classes
freeusregions-html5-mapfreeusregionsHtml5MapBoldnav-tab-active
HTML Comments
Temporary workaround for tinymce bug, when it's not focusable in modal windows.When comressed_scriptes is disabled - compat3x plugin for tinymcy will be added,this will prevent bug from occurring.
Data Attributes
original-title
JS Globals
freeusregions_html5map_plugin_get_optionsfreeusregions_html5map_plugin_get_static_url
Shortcode Output
[freeusregionshtml5map id="
FAQ

Frequently Asked Questions about Interactive US Map – Create Clickable & Customizable U.S. Maps