Interactive UK Map Security & Risk Analysis

wordpress.org/plugins/interactive-uk-map

Free WordPress plugin for embedding an interactive United Kingdom map with clickable regions. Easy to install and configure.

100 active installs v3.4.9 PHP + WP 3.3+ Updated Dec 3, 2025
html5-mapinteractive-mapjavascriptmapmaps
98
A · Safe
CVEs total1
Unpatched0
Last CVEDec 30, 2024
Safety Verdict

Is Interactive UK Map Safe to Use in 2026?

Generally Safe

Score 98/100

Interactive UK Map has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Dec 30, 2024Updated 4mo ago
Risk Assessment

The "interactive-uk-map" v3.4.9 plugin exhibits a mixed security posture. On the positive side, it utilizes prepared statements for all SQL queries and avoids external HTTP requests. However, significant concerns arise from its attack surface, with 4 out of 6 entry points lacking proper authentication checks. This includes all AJAX handlers, presenting a high risk of unauthorized actions if exploited. The taint analysis shows a concerning number of flows with unsanitized paths, though thankfully no critical or high severity issues were identified in this version.

The plugin's vulnerability history is a significant red flag. It has a documented high-severity CVE and a past vulnerability type of Cross-Site Request Forgery (CSRF). The fact that the last vulnerability was recently discovered (December 2024) and is currently unpatched for this version suggests a recurring pattern of security weaknesses. While the current version has no *unpatched* CVEs, the historical context combined with the identified unprotected entry points and taint flows indicates a need for caution and prompt updates when new vulnerabilities are discovered.

In conclusion, the plugin demonstrates some good security practices like prepared SQL statements. However, the substantial attack surface without authentication, along with a history of significant vulnerabilities, creates a notable risk profile. Users should be vigilant about updates and consider the potential for exploitation of the unprotected entry points.

Key Concerns

  • Unprotected AJAX handlers
  • Significant number of unsanitized paths in taint analysis
  • High severity CVE in vulnerability history
  • 16% of output properly escaped
  • Large attack surface without auth
Vulnerabilities
1

Interactive UK Map Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2024-56267high · 8.2Cross-Site Request Forgery (CSRF)

Interactive UK Map <= 3.4.8 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Dec 30, 2024 Patched in 3.4.9 (10d)
Code Analysis
Analyzed Mar 16, 2026

Interactive UK Map Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
259
51 escaped
Nonce Checks
8
Capability Checks
1
File Operations
16
External Requests
0
Bundled Libraries
0

Output Escaping

16% escaped310 total outputs
Data Flows
9 unsanitized

Data Flow Analysis

11 flows9 with unsanitized paths
<editmainconfig> (editmainconfig.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Interactive UK Map Attack Surface

Entry Points6
Unprotected4

AJAX Handlers 4

authwp_ajax_freeukregionshtml5map_settings_jsfreeukregionsmap.php:687
noprivwp_ajax_freeukregionshtml5map_settings_jsfreeukregionsmap.php:688
authwp_ajax_freeukregionshtml5map_state_infofreeukregionsmap.php:704
noprivwp_ajax_freeukregionshtml5map_state_infofreeukregionsmap.php:705

Shortcodes 2

[freeukregionshtml5map] freeukregionsmap.php:191
[freeukregionmap01] freeukregionsmap.php:1456
WordPress Hooks 10
actionplugins_loadedfreeukregionsmap.php:21
actionadmin_menufreeukregionsmap.php:28
actionadmin_initfreeukregionsmap.php:151
actionwp_enqueue_scriptsfreeukregionsmap.php:182
actionadmin_footerfreeukregionsmap.php:629
actionwp_footerfreeukregionsmap.php:631
actioninitfreeukregionsmap.php:707
filterwidget_textfreeukregionsmap.php:1084
filteruser_has_capfreeukregionsmap.php:1353
actioninitfreeukregionsmap.php:1438
Maintenance & Trust

Interactive UK Map Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 3, 2025
PHP min version
Downloads8K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Interactive UK Map Developer Profile

html5maps

6 plugins · 7K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
347 days
View full developer profile
Detection Fingerprints

How We Detect Interactive UK Map

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/interactive-uk-map/static/css/mapadm.css/wp-content/plugins/interactive-uk-map/static/css/tipsy.css/wp-content/plugins/interactive-uk-map/static/js/admin.js/wp-content/plugins/interactive-uk-map/static/js/freeukregionshtml5map.js/wp-content/plugins/interactive-uk-map/static/js/jquery.min.js/wp-content/plugins/interactive-uk-map/static/js/jquery.tipsy.js/wp-content/plugins/interactive-uk-map/static/js/tinymce.min.js
Script Paths
/wp-content/plugins/interactive-uk-map/static/js/jquery.min.js
Version Parameters
/static/css/mapadm.css?ver=3.4.9

HTML / DOM Fingerprints

CSS Classes
freeukregions-html5-mapfreeukregionsHtml5MapBoldnav-tabnav-tab-activetipsy-qwrap freeukregions-html5-map main fullleft-blockqanner
Data Attributes
original-title
JS Globals
freeukregions_html5map_plugin_get_optionsfreeukregions_html5map_plugin_get_static_url
Shortcode Output
[freeukregionshtml5map id=
FAQ

Frequently Asked Questions about Interactive UK Map