Interactive World Maps Clickable Security & Risk Analysis

wordpress.org/plugins/interactive-world-maps-wp

Add an interactive world map to your WordPress site! Customize colors, links, hover, and images. Use a simple shortcode to display it anywhere!

0 active installs v1.0.0 PHP 5.2+ WP 5.2+ Updated Unknown
google-mapinteractive-mapsvg-mapus-mapworld-map
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Interactive World Maps Clickable Safe to Use in 2026?

Generally Safe

Score 100/100

Interactive World Maps Clickable has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "interactive-world-maps-wp" plugin v1.0.0 exhibits a generally good security posture, with strong adherence to secure coding practices. The complete absence of dangerous functions, SQL injection vulnerabilities (all queries use prepared statements), and output escaping issues are significant strengths. The plugin also demonstrates a clean vulnerability history with no recorded CVEs, suggesting a proactive or fortunate development approach.

However, there are notable areas of concern. The plugin exposes 8 AJAX handlers, and critically, 2 of these lack authentication checks. This creates a significant attack surface where unauthenticated users could potentially trigger these handlers, leading to unintended actions or information disclosure depending on their functionality. While taint analysis shows no critical or high severity unsanitized paths, the presence of unprotected AJAX endpoints warrants careful investigation into the specific actions they perform. The limited number of nonce checks (3) against the number of AJAX handlers also suggests potential gaps in input validation for some handlers.

In conclusion, while the core code quality and vulnerability history are positive indicators, the unprotected AJAX endpoints represent a clear and present risk. Addressing these authentication gaps should be the immediate priority for improving the plugin's overall security.

Key Concerns

  • Unprotected AJAX handlers
  • Limited nonce checks for AJAX handlers
Vulnerabilities
None known

Interactive World Maps Clickable Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Interactive World Maps Clickable Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
5 prepared
Unescaped Output
0
18 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared5 total queries

Output Escaping

100% escaped18 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
ikrwmap_data_edit (functions\functions.php:237)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Interactive World Maps Clickable Attack Surface

Entry Points9
Unprotected2

AJAX Handlers 8

authwp_ajax_ikrwmap_save_data_addfunctions\functions.php:230
noprivwp_ajax_ikrwmap_save_data_addfunctions\functions.php:231
authwp_ajax_ikrwmap_data_editfunctions\functions.php:327
authwp_ajax_noprive_ikrwmap_data_editfunctions\functions.php:328
authwp_ajax_ikrwmap_world_mapDeletefunctions\functions.php:381
authwp_ajax_noprive_ikrwmap_world_mapDeletefunctions\functions.php:382
authwp_ajax_ikrwmap_retrieveData_from_dbfunctions\functions.php:412
noprivwp_ajax_ikrwmap_retrieveData_from_dbfunctions\functions.php:413

Shortcodes 1

[ikrwmap_world_map] includes\ikrwmap_shortcode.php:22
WordPress Hooks 4
actionadmin_enqueue_scriptsfunctions\functions.php:54
actionadmin_enqueue_scriptsfunctions\functions.php:76
actionwp_enqueue_scriptsfunctions\functions.php:104
actionadmin_menuinteractive-world-maps-clickable.php:42
Maintenance & Trust

Interactive World Maps Clickable Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedUnknown
PHP min version5.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Interactive World Maps Clickable Developer Profile

IK Robin

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Interactive World Maps Clickable

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/interactive-world-maps-wp/assets/js/ikrwmap-interactivity.js/wp-content/plugins/interactive-world-maps-wp/assets/js/ikrwmap-zoom.js/wp-content/plugins/interactive-world-maps-wp/assets/js/worldmap-global.js/wp-content/plugins/interactive-world-maps-wp/assets/js/ikrwmap-images.js/wp-content/plugins/interactive-world-maps-wp/assets/js/ikrwmap-bootstrap.js/wp-content/plugins/interactive-world-maps-wp/assets/style/style.css/wp-content/plugins/interactive-world-maps-wp/assets/style/ikrwmap-bootstrap.css/wp-content/plugins/interactive-world-maps-wp/assets/js/ikrwmap-fontend-script.js+1 more
Script Paths
../assets/js/ikrwmap-interactivity.js../assets/js/ikrwmap-zoom.js../assets/js/worldmap-global.js../assets/js/ikrwmap-images.js../assets/js/ikrwmap-bootstrap.js../assets/js/ikrwmap-fontend-script.js
Version Parameters
interactive-world-maps-wp/assets/js/ikrwmap-interactivity.js?ver=interactive-world-maps-wp/assets/js/ikrwmap-zoom.js?ver=interactive-world-maps-wp/assets/js/worldmap-global.js?ver=interactive-world-maps-wp/assets/js/ikrwmap-images.js?ver=interactive-world-maps-wp/assets/js/ikrwmap-bootstrap.js?ver=interactive-world-maps-wp/assets/style/style.css?ver=interactive-world-maps-wp/assets/style/ikrwmap-bootstrap.css?ver=interactive-world-maps-wp/assets/js/ikrwmap-fontend-script.js?ver=interactive-world-maps-wp/assets/style/ikrwmap-fontend-style.css?ver=

HTML / DOM Fingerprints

CSS Classes
robingeo-containermap_containermap-imgmap-data-showinput-formlocation-limit-messagehidden
Data Attributes
data-iddata-titledata-desdata-hov_colordata-fill_colorsdata-fill_color+4 more
JS Globals
your_ajax_objectikrwmap_get_url
REST Endpoints
/wp-json/ikrwmap/v1/save_data/wp-json/ikrwmap/v1/get_data/wp-json/ikrwmap/v1/update_data/wp-json/ikrwmap/v1/delete_data
Shortcode Output
[ikrwmap_world_map]
FAQ

Frequently Asked Questions about Interactive World Maps Clickable