Interactive US Map Security & Risk Analysis

wordpress.org/plugins/interactive-us-map

Interactive US Regional Map WordPress plugin with an easy to use map dashboard.

400 active installs v2.7 PHP + WP 3.4+ Updated Apr 27, 2025
clickable-mapsinteractive-mapsus-mapus-map-templateusa-maps
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEApr 9, 2025
Safety Verdict

Is Interactive US Map Safe to Use in 2026?

Mostly Safe

Score 78/100

Interactive US Map is generally safe to use. 1 past CVE were resolved. Keep it updated.

1 known CVE 1 unpatched Last CVE: Apr 9, 2025Updated 11mo ago
Risk Assessment

The "interactive-us-map" v2.7 plugin exhibits a generally good security posture with several positive indicators. The plugin demonstrates strong adherence to secure coding practices, with a high percentage of properly escaped outputs and 100% of SQL queries utilizing prepared statements. The attack surface is minimal, with only one shortcode identified and no unprotected entry points in terms of AJAX handlers or REST API routes. However, the plugin has a concerning vulnerability history. The presence of one unpatched medium severity CVE, which is a Cross-Site Request Forgery (CSRF), indicates a potential risk that users could be exploited by malicious actors. Furthermore, while the static analysis shows no critical or high severity taint flows, the single flow with unsanitized paths warrants attention. The absence of nonce checks is a significant concern, especially when combined with the historical CSRF vulnerability, as it leaves the plugin susceptible to various attacks that leverage user interactions. In conclusion, while the plugin has solid foundations in secure coding, the unpatched CVE and the lack of nonce checks are notable weaknesses that require immediate attention to mitigate potential security risks.

Key Concerns

  • Unpatched medium severity CVE
  • Flows with unsanitized paths
  • No nonce checks
Vulnerabilities
1

Interactive US Map Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-32661medium · 6.1Cross-Site Request Forgery (CSRF)

Interactive US Map <= 2.7 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Apr 9, 2025Unpatched
Code Analysis
Analyzed Mar 16, 2026

Interactive US Map Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
9
230 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

TinyMCE

Output Escaping

96% escaped239 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
updateOptions (usr-map.php:121)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Interactive US Map Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[usr_map] usr-map.php:57
WordPress Hooks 5
actionadmin_menuusr-map.php:49
actionadmin_footerusr-map.php:50
actionwp_footerusr-map.php:51
actionadmin_enqueue_scriptsusr-map.php:52
actioninitusr-map.php:53
Maintenance & Trust

Interactive US Map Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 27, 2025
PHP min version
Downloads19K

Community Trust

Rating100/100
Number of ratings3
Active installs400
Developer Profile

Interactive US Map Developer Profile

WP Map Plugins

7 plugins · 2K total installs

77
trust score
Avg Security Score
84/100
Avg Patch Time
81 days
View full developer profile
Detection Fingerprints

How We Detect Interactive US Map

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/interactive-us-map/public/css/map-style.css/wp-content/plugins/interactive-us-map/public/js/map-interact.js/wp-content/plugins/interactive-us-map/public/css/dashboard-style.css/wp-content/plugins/interactive-us-map/public/css/tinyeditor.css/wp-content/plugins/interactive-us-map/public/js/editor/tinymce.min.js/wp-content/plugins/interactive-us-map/public/js/editor/scripts.js
Script Paths
/wp-content/plugins/interactive-us-map/public/js/map-interact.js/wp-content/plugins/interactive-us-map/public/js/editor/tinymce.min.js/wp-content/plugins/interactive-us-map/public/js/editor/scripts.js
Version Parameters
interactive-us-map/public/js/map-interact.js?t=interactive-us-map/public/css/map-style.cssinteractive-us-map/public/js/map-interact.jsinteractive-us-map/public/css/dashboard-style.cssinteractive-us-map/public/css/tinyeditor.cssinteractive-us-map/public/js/editor/tinymce.min.jsinteractive-us-map/public/js/editor/scripts.js

HTML / DOM Fingerprints

Data Attributes
usr_mapusrbrdrclrusrshowvisnsusrvisnsusrvisnshoverusrshowlakes+8 more
JS Globals
USRMapUSRMAP_VERSIONUSRMAP_DIRUSRMAP_URL
Shortcode Output
<div id="usr-map"></div><script>var usr_map_options = {'usrbrdrclr':'usrshowvisns':
FAQ

Frequently Asked Questions about Interactive US Map