Interactive UK Regional Map Security & Risk Analysis

wordpress.org/plugins/interactive-uk-regional-map

Interactive UK regional map WordPress plugin with an easy to use admin panel interface.

20 active installs v2.0 PHP + WP 3.4+ Updated Apr 27, 2025
clickable-mapsinteractive-mapsuk-mapuk-map-templateuk-maps
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEJun 5, 2025
Safety Verdict

Is Interactive UK Regional Map Safe to Use in 2026?

Mostly Safe

Score 78/100

Interactive UK Regional Map is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Jun 5, 2025Updated 11mo ago
Risk Assessment

The "interactive-uk-regional-map" plugin v2.0 presents a mixed security posture. While it demonstrates good practices by having no direct SQL queries or file operations, and no external HTTP requests, several critical areas raise significant concerns. The lack of output escaping on all 44 identified output points is a major vulnerability, opening the door for Cross-Site Scripting (XSS) attacks. Furthermore, the taint analysis revealing two flows with unsanitized paths, though not classified as critical or high severity, indicates potential risks in how data is processed. The plugin's vulnerability history, particularly the existence of a currently unpatched medium severity CVE, points to a recurring issue with security flaws, specifically CSRF, which is concerning given the plugin's age and the nature of past vulnerabilities.

Overall, the plugin has potential strengths in its minimal attack surface from a direct code execution perspective and its use of prepared statements for database interactions. However, the pervasive lack of output escaping and the presence of an unpatched vulnerability significantly detract from its security. The data suggests a developer who may not prioritize robust security hardening, especially regarding output sanitation and timely patching of known issues. The unsanitized taint flows also warrant closer inspection to understand the potential impact despite their current severity classification. Until these issues are addressed, the plugin should be considered a moderate to high security risk.

Key Concerns

  • Unpatched medium severity CVE
  • 0% output escaping
  • 2 flows with unsanitized paths
  • No nonce checks
  • No capability checks
  • Bundled outdated TinyMCE v1.0
Vulnerabilities
1

Interactive UK Regional Map Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-49445medium · 4.3Cross-Site Request Forgery (CSRF)

Interactive UK Regional Map <= 2.0 - Cross-Site Request Forgery

Jun 5, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Interactive UK Regional Map Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
44
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE1.0

Output Escaping

0% escaped44 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
__construct (ukr-map.php:13)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Interactive UK Regional Map Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[ukr_map] ukr-map.php:20
WordPress Hooks 4
actionadmin_menuukr-map.php:16
actionadmin_footerukr-map.php:17
actionwp_footerukr-map.php:18
actionadmin_enqueue_scriptsukr-map.php:19
Maintenance & Trust

Interactive UK Regional Map Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 27, 2025
PHP min version
Downloads4K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Interactive UK Regional Map Developer Profile

WP Map Plugins

7 plugins · 2K total installs

77
trust score
Avg Security Score
84/100
Avg Patch Time
81 days
View full developer profile
Detection Fingerprints

How We Detect Interactive UK Regional Map

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/interactive-uk-regional-map/map-style.css/wp-content/plugins/interactive-uk-regional-map/map-interact.js/wp-content/plugins/interactive-uk-regional-map/style.css/wp-content/plugins/interactive-uk-regional-map/tinyeditor.css/wp-content/plugins/interactive-uk-regional-map/js/tinymce.min.js/wp-content/plugins/interactive-uk-regional-map/js/scripts.js
Script Paths
/wp-content/plugins/interactive-uk-regional-map/map-interact.js/wp-content/plugins/interactive-uk-regional-map/js/tinymce.min.js/wp-content/plugins/interactive-uk-regional-map/js/scripts.js
Version Parameters
interactive-uk-regional-map/map-style.css?ver=interactive-uk-regional-map/map-interact.js?ver=interactive-uk-regional-map/style.css?ver=interactive-uk-regional-map/tinyeditor.css?ver=interactive-uk-regional-map/js/tinymce.min.js?ver=interactive-uk-regional-map/js/scripts.js?ver=

HTML / DOM Fingerprints

CSS Classes
ukr-map-canvas
HTML Comments
<!-- UKR_MAP_DATA_START --><!-- UKR_MAP_DATA_END -->
Data Attributes
data-ukr-map
JS Globals
ukr_map_options
Shortcode Output
[ukr_map]
FAQ

Frequently Asked Questions about Interactive UK Regional Map