SimpleMaps Security & Risk Analysis

wordpress.org/plugins/interactive-maps

Easily add an interactive map of the world, US, or many other countries to your WordPress site.

600 active installs v0.99.3 PHP + WP 2.5+ Updated Aug 4, 2025
clickable-mapinteractive-mapsimplemapsus-mapworld-map
99
A · Safe
CVEs total1
Unpatched0
Last CVEApr 17, 2025
Safety Verdict

Is SimpleMaps Safe to Use in 2026?

Generally Safe

Score 99/100

SimpleMaps has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Apr 17, 2025Updated 8mo ago
Risk Assessment

The "interactive-maps" plugin v0.99.3 exhibits a generally good security posture based on the provided static analysis. The code demonstrates strong adherence to secure coding practices, with a high percentage of properly escaped outputs, 100% of SQL queries using prepared statements, and a significant number of nonce and capability checks. There are no identified critical or high severity taint flows, and the plugin's attack surface appears well-controlled, with no unprotected entry points found in this analysis. However, the plugin's vulnerability history is a notable concern. A past medium-severity vulnerability, specifically Cross-Site Request Forgery (CSRF), was recorded. While currently unpatched, this indicates a recurring area of weakness. The fact that the last vulnerability was in the future (2025) is unusual and could indicate a data anomaly or a placeholder for future patching. Overall, while the current code seems robust, the historical presence of CSRF vulnerabilities warrants continued vigilance and proactive security auditing.

Key Concerns

  • Past medium severity vulnerability (CSRF)
Vulnerabilities
1

SimpleMaps Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-39424medium · 4.3Cross-Site Request Forgery (CSRF)

Simple Maps <= 0.98 - Cross-Site Request Forgery

Apr 17, 2025 Patched in 0.99 (35d)
Code Analysis
Analyzed Mar 16, 2026

SimpleMaps Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
58 escaped
Nonce Checks
6
Capability Checks
5
File Operations
1
External Requests
0
Bundled Libraries
0

Output Escaping

97% escaped60 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
processMapDataUpload (includes\class-map-form.php:135)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

SimpleMaps Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[simplemaps] interactive-maps.php:139
WordPress Hooks 9
filterupload_mimesinteractive-maps.php:23
filterwp_check_filetype_and_extinteractive-maps.php:29
actionadmin_menuinteractive-maps.php:40
actionadmin_enqueue_scriptsinteractive-maps.php:55
actionadmin_post_simplemaps_delete_mapinteractive-maps.php:67
actionadmin_post_simplemaps_create_mapinteractive-maps.php:90
actionadmin_post_simplemaps_replace_mapinteractive-maps.php:117
actioninitinteractive-maps.php:208
actioninitinteractive-maps.php:223
Maintenance & Trust

SimpleMaps Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 4, 2025
PHP min version
Downloads37K

Community Trust

Rating96/100
Number of ratings10
Active installs600
Developer Profile

SimpleMaps Developer Profile

simplemaps

1 plugin · 600 total installs

87
trust score
Avg Security Score
99/100
Avg Patch Time
35 days
View full developer profile
Detection Fingerprints

How We Detect SimpleMaps

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/interactive-maps/assets/css/admin.css/wp-content/plugins/interactive-maps/assets/js/admin.js
Script Paths
/wp-content/plugins/interactive-maps/assets/js/admin.js
Version Parameters
simplemaps-admin-css?ver=simplemaps-admin-js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- SimpleMaps: Please complete the migration process --><!-- SimpleMaps: Map not found or not configured -->
JS Globals
simplemaps_admin_post_url
Shortcode Output
[simplemaps]
FAQ

Frequently Asked Questions about SimpleMaps