
Leaflet Map Security & Risk Analysis
wordpress.org/plugins/leaflet-mapInteractive maps and markers on your posts and pages with simple shortcodes.
Is Leaflet Map Safe to Use in 2026?
Generally Safe
Score 95/100Leaflet Map has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The leaflet-map plugin v3.4.4 presents a mixed security profile. On the positive side, the plugin exhibits good practices in several key areas, including the complete absence of SQL queries that are not prepared and a lack of known unpatched vulnerabilities. The attack surface appears to be minimal, with no identified AJAX handlers, REST API routes, shortcodes, or cron events that are directly exposed to external input without authentication. However, significant concerns arise from the static analysis. The low percentage of properly escaped output (13%) is a major red flag, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially given that XSS has been a common vulnerability type in its history. Furthermore, a taint analysis revealed one flow with unsanitized paths, suggesting a potential for path traversal or other file-related vulnerabilities, even though it was not classified as critical or high severity.
Key Concerns
- Low percentage of properly escaped output
- Taint flow with unsanitized paths
- History of Cross-Site Scripting vulnerabilities
- History of Cross-Site Request Forgery vulnerabilities
Leaflet Map Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Leaflet Map <= 3.4.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Leaflet Map <= 3.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Leaflet Map <= 2.23.3 - Contributor+ Stored Cross-Site Scripting
Leaflet Map < 3.0.0 - Cross-Site Request Forgery to Stored Cross-Site Scripting
Leaflet Map Release Timeline
Leaflet Map Code Analysis
Output Escaping
Data Flow Analysis
Leaflet Map Attack Surface
WordPress Hooks 7
Maintenance & Trust
Leaflet Map Maintenance & Trust
Maintenance Signals
Community Trust
Leaflet Map Alternatives
Simple Map Locator
simple-map-locator
Interactive maps and markers on your posts and pages with simple shortcodes.
Open User Map
open-user-map
Engage your visitors with an interactive map – let them add markers instantly or create a custom map showcasing your favorite spots.
Ultimate Maps by Supsystic
ultimate-maps-by-supsystic
Ultimate Maps by Supsystic is the best Google Maps alternative. It includes OpenStreetMap (OSM), Bing Maps, MapBox and Thunderforest maps services
ACF OpenStreetMap Field
acf-openstreetmap-field
A configurable OpenStreetMap Field for ACF.
Out of the Block: OpenStreetMap
ootb-openstreetmap
A map block for Gutenberg using OpenStreetMap and Leaflet that needs no API keys and works out of the box. Or should we say, ...Out of the Block?
Leaflet Map Developer Profile
1 plugin · 30K total installs
How We Detect Leaflet Map
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/leaflet-map/style.css/wp-content/plugins/leaflet-map/scripts/shortcode-helper.js/wp-content/plugins/leaflet-map/scripts/shortcode-helper.min.jsscripts/shortcode-helper.jsscripts/shortcode-helper.min.jsleaflet-map/style.css?ver=shortcode-helper.js?ver=shortcode-helper.min.js?ver=HTML / DOM Fingerprints
leaflet-map-containerdata-leaflet-map-optionsLeafletMap[leaflet-map][leaflet-geojson][leaflet-image][leaflet-kml]