Interactive Polish Map Security & Risk Analysis

wordpress.org/plugins/interactive-polish-map

Interactive map of Poland, which allows you to attach links to the region.

500 active installs v1.2.1 PHP + WP 6.0+ Updated Feb 22, 2025
interactivepolandpolish-mapvoivodeship
92
A · Safe
CVEs total1
Unpatched0
Last CVEJan 19, 2023
Safety Verdict

Is Interactive Polish Map Safe to Use in 2026?

Generally Safe

Score 92/100

Interactive Polish Map has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jan 19, 2023Updated 1yr ago
Risk Assessment

The "interactive-polish-map" plugin v1.2.1 exhibits a mixed security posture. On the positive side, static analysis reveals no dangerous functions, SQL queries are all prepared, and there are no file operations or external HTTP requests. Taint analysis also indicates no critical or high severity vulnerabilities. This suggests a generally good development practice in terms of preventing common attack vectors like SQL injection and arbitrary file operations.

However, several areas raise concerns. The plugin has a history of one medium severity Cross-site Scripting (XSS) vulnerability, with the last known vulnerability being in early 2023. While this specific version (1.2.1) is not listed as unpatched, the past XSS issue indicates a potential for input sanitization weaknesses. Furthermore, the static analysis shows 0 nonce checks and 0 capability checks for its single shortcode entry point. This is a significant concern, as it means that any user, regardless of their role or permissions, can execute the functionality associated with the shortcode. Coupled with 78% proper output escaping, there's a risk that the 22% of unescaped output could be leveraged by an attacker if the shortcode handles user-supplied data in a way that leads to XSS.

In conclusion, while the plugin has strengths in its secure handling of SQL and its avoidance of dangerous functions, the lack of authentication and capability checks on its shortcode, combined with a past XSS vulnerability and some unescaped output, present notable risks. The absence of checks on the shortcode is the most pressing issue, potentially allowing unauthorized actions or data exposure.

Key Concerns

  • No nonce checks for shortcode
  • No capability checks for shortcode
  • Unescaped output present (22%)
  • Past medium XSS vulnerability
Vulnerabilities
1 published

Interactive Polish Map Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-23821medium · 6.6Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Interactive Polish Map <= 1.2 - Authenticated (Admi+) Stored Cross-Site Scripting

Jan 19, 2023 Patched in 1.2.1 (369d)
Version History

Interactive Polish Map Release Timeline

v1.2.1Current
v1.21 CVE
v1.11 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Interactive Polish Map Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
7 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

78% escaped9 total outputs
Attack Surface

Interactive Polish Map Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[mapa-polski] interactive-polish-map.php:227
WordPress Hooks 6
actioninitinteractive-polish-map.php:20
filterplugin_row_metainteractive-polish-map.php:214
actionadmin_menuinteractive-polish-map.php:224
actionadmin_initinteractive-polish-map.php:225
actioninitinteractive-polish-map.php:226
actionwidgets_initsnippets\widget_map.php:137
Maintenance & Trust

Interactive Polish Map Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 22, 2025
PHP min version
Downloads15K

Community Trust

Rating94/100
Number of ratings3
Active installs500
Developer Profile

Interactive Polish Map Developer Profile

Marcin Pietrzak

23 plugins · 89K total installs

77
trust score
Avg Security Score
97/100
Avg Patch Time
274 days
View full developer profile
Detection Fingerprints

How We Detect Interactive Polish Map

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/interactive-polish-map/assets/js/interactive_polish_map.js/wp-content/plugins/interactive-polish-map/assets/style/interactive_polish_map.css
Script Paths
/wp-content/plugins/interactive-polish-map/assets/js/interactive_polish_map.js
Version Parameters
interactive_polish_map.js?ver=interactive_polish_map.css?ver=

HTML / DOM Fingerprints

CSS Classes
wipm_type
HTML Comments
<!-- snippets --><!-- init -->
Data Attributes
id="ipm_type_"id="w"id="w"
Shortcode Output
<div id="ipm_type_"><ul id="w" class=""><li id="w
FAQ

Frequently Asked Questions about Interactive Polish Map