Leaflet Map Widget Security & Risk Analysis

wordpress.org/plugins/leaflet-map-widget

This is a extra widget for the Leaflet Map plugin

40 active installs v0.2 PHP + WP 3.0.1+ Updated Jan 28, 2021
leafletmapwidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Leaflet Map Widget Safe to Use in 2026?

Generally Safe

Score 85/100

Leaflet Map Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The leaflet-map-widget plugin v0.2 exhibits a generally strong security posture based on the provided static analysis. The absence of any detected dangerous functions, raw SQL queries, file operations, or external HTTP requests is a significant positive. Furthermore, the plugin demonstrates good practices in output escaping, with a high percentage of outputs being properly sanitized. The lack of any recorded vulnerabilities or CVEs in its history also suggests a mature and well-maintained codebase, or at least one that has not been a target for past exploits. The plugin's attack surface is commendably small, with no identified AJAX handlers, REST API routes, shortcodes, or cron events, and critically, none of these entry points are unprotected.

However, a notable concern arises from the complete absence of nonce and capability checks. While the current attack surface is zero, this indicates a potential weakness if new entry points are introduced in future versions without proper authentication and authorization mechanisms. Taint analysis also reported zero flows, which is positive, but this might be limited by the scope of the analysis performed. The lack of any identified vulnerabilities is reassuring, but it's important to remember that no code is entirely invulnerable, and the absence of a history doesn't guarantee future security. Overall, the plugin is currently in a secure state, but the reliance on a small attack surface for security rather than explicit checks presents a latent risk for future development.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

Leaflet Map Widget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Leaflet Map Widget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
27 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

87% escaped31 total outputs
Attack Surface

Leaflet Map Widget Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwidgets_initleaflet-map-widget.php:39
actioninitleaflet-map-widget.php:41
Maintenance & Trust

Leaflet Map Widget Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedJan 28, 2021
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

Leaflet Map Widget Developer Profile

theode

11 plugins · 220 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Leaflet Map Widget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
[leaflet-map address=[leaflet-marker]
FAQ

Frequently Asked Questions about Leaflet Map Widget