
LB GMaps Security & Risk Analysis
wordpress.org/plugins/lb-gmapsJust another Google Maps plugin but simpler and with a live preview.
Is LB GMaps Safe to Use in 2026?
Generally Safe
Score 85/100LB GMaps has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The lb-gmaps plugin version 1.0 presents a mixed security posture with some concerning areas despite a lack of known historical vulnerabilities. While it exhibits strengths such as no recorded CVEs and zero critical or high severity taint flows, indicating a generally clean history and development focus, several code signals raise red flags. The presence of an unprotected AJAX handler is a significant concern, as it represents a direct entry point that could be exploited by attackers without any authentication or authorization checks. Furthermore, the complete lack of output escaping across all identified outputs is a critical weakness, opening the door to Cross-Site Scripting (XSS) vulnerabilities. Any user-supplied data rendered on the frontend without proper escaping is a potential vector for malicious code injection.
The plugin's 40% use of prepared statements for SQL queries is a positive step towards preventing SQL injection, but the remaining 60% without this protection still poses a risk. The absence of capability checks is also noteworthy; even if authentication were present on AJAX actions, without capability checks, any authenticated user could potentially trigger unintended actions. The plugin's vulnerability history being empty is a positive sign, suggesting good development practices or a lack of past scrutiny, but it cannot negate the identified risks within the current codebase. In conclusion, while the plugin has no known exploitable vulnerabilities in its history, the current static analysis reveals several critical security weaknesses, particularly the unprotected AJAX handler and the universal lack of output escaping, which require immediate attention.
Key Concerns
- Unprotected AJAX handler
- No output escaping
- SQL queries without prepared statements
- No capability checks
LB GMaps Security Vulnerabilities
LB GMaps Code Analysis
SQL Query Safety
Output Escaping
LB GMaps Attack Surface
AJAX Handlers 5
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
LB GMaps Maintenance & Trust
Maintenance Signals
Community Trust
LB GMaps Alternatives
Map Engine – Google Maps and Open Street Maps for WordPress
map-engine
An Ultimate map tool to revolutionize your map building experience.
WP Go Maps (formerly WP Google Maps)
wp-google-maps
The easiest to use Google maps plugin! Create a custom Google map, map block, store locator or map widget with high quality markers containing categor …
Easy Google Maps
google-maps-easy
Google Maps with markers, locations and clusterization, KML layers and filters. Custom Google map markers with text, images, videos, links.
Maps Plugin using Google Maps for WordPress – WP Google Map
gmap-embed
Google Map plugin for WordPress is very Simple, light-weight and Easy to use Google Custom Map with markers in Posts, Pages, Sidebar as shortcode.
Simple Shortcode for Google Maps
simple-google-maps-short-code
A simple shortcode for embedding Google Maps in any WordPress post, page or widget.
LB GMaps Developer Profile
1 plugin · 0 total installs
How We Detect LB GMaps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/lb-gmaps/assets/js/lb_gmaps_live_preview.js/wp-content/plugins/lb-gmaps/assets/js/lb_gmaps_helper_functions.js/wp-content/plugins/lb-gmaps/assets/css/lb_gmaps_metabox.css/wp-content/plugins/lb-gmaps/assets/css/lb_gmaps_infowindow.css/wp-content/plugins/lb-gmaps/assets/css/lb_gmaps_shared.csshttps://maps.googleapis.com/maps/api/js?key=//maxcdn.bootstrapcdn.com/font-awesome/4.7.0/css/font-awesome.min.cssHTML / DOM Fingerprints
lb-gmaps-metaboxlb-gmaps-infowindowlb-gmaps-shareddata-map-iddata-marker-idLB_GMaps_HelperLB_GMaps_AjaxerLB_GMaps_Metabox_HandlerLB_GMaps_Shortcode_HandlerLB_GMaps_Post_TypeLB_GMaps_Settings_Handler+4 more[lb-gmaps][lb-gmaps map_id=