Iran Map Security & Risk Analysis

wordpress.org/plugins/iran-map

Add minimal and nice iran map to your WordPress web site.

100 active installs v1.0.0 PHP 5.2.4+ WP 4.0+ Updated Sep 12, 2018
farsiiraniran-mappersian%d9%86%d9%82%d8%b4%d9%87-%d8%a7%db%8c%d8%b1%d8%a7%d9%86
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Iran Map Safe to Use in 2026?

Generally Safe

Score 85/100

Iran Map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7yr ago
Risk Assessment

The "iran-map" plugin v1.0.0 exhibits a generally positive security posture based on the provided static analysis. The plugin has a minimal attack surface with only one shortcode identified and no AJAX handlers or REST API routes. Critically, there are no unprotected entry points, suggesting that all identified interfaces are either protected by authentication or capability checks. The code analysis further reveals good practices such as 100% of SQL queries using prepared statements and a high rate of output escaping (89%). There are no indications of dangerous functions, file operations, or external HTTP requests, which are common sources of vulnerabilities. Furthermore, the plugin demonstrates the use of capability checks, which is a positive indicator of secure coding. The absence of any known historical vulnerabilities (CVEs) or identified taint flows further bolsters its perceived security. However, a notable concern is the absence of any nonce checks on the identified entry point (the shortcode). While the shortcode itself is not directly identified as an unprotected entry point, the lack of nonce checks leaves it susceptible to CSRF attacks if it performs any sensitive actions or modifies data. This, coupled with the very limited taint analysis (0 flows analyzed), means that complex or subtle vulnerabilities might have been missed. Despite these minor concerns, the plugin's current state appears relatively secure.

Key Concerns

  • Missing nonce check on shortcode
Vulnerabilities
None known

Iran Map Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Iran Map Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
68 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

89% escaped76 total outputs
Attack Surface

Iran Map Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[display_iran_map] public\display-map.php:373
WordPress Hooks 4
actionadmin_menuadmin\admin-menu.php:28
actionadmin_initadmin\settings-register.php:371
actioninitcore\core-functions.php:54
actionplugins_loadediran-map.php:70
Maintenance & Trust

Iran Map Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedSep 12, 2018
PHP min version5.2.4
Downloads3K

Community Trust

Rating60/100
Number of ratings2
Active installs100
Developer Profile

Iran Map Developer Profile

Ali Taee

1 plugin · 100 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Iran Map

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/iran-map/public/css/green.css/wp-content/plugins/iran-map/public/css/full.css/wp-content/plugins/iran-map/public/css/black.css/wp-content/plugins/iran-map/public/css/blue.css/wp-content/plugins/iran-map/public/css/cyan.css

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Iran Map