
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) Security & Risk Analysis
wordpress.org/plugins/leaflet-maps-markerThe most comprehensive & user-friendly mapping solution for WordPress
Is Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) Safe to Use in 2026?
Generally Safe
Score 94/100Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) has a strong security track record. Known vulnerabilities have been patched promptly.
The Leaflet Maps Marker plugin v3.12.10 exhibits a mixed security posture. While the plugin has a small attack surface with only one unprotected AJAX handler, and a good number of capability checks and nonces present, concerns arise from the code analysis. A significant portion of SQL queries (44%) are not using prepared statements, presenting a potential SQL injection risk. Furthermore, less than half of the output operations are properly escaped, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities. The vulnerability history shows a pattern of common web vulnerabilities like XSS and SQL injection, with several high and medium severity CVEs historically. The fact that there are currently no unpatched vulnerabilities is positive, but the repeated nature of these vulnerability types suggests a need for more robust input validation and output sanitization practices.
Key Concerns
- SQL queries not using prepared statements
- Output escaping is not properly implemented
- Bundled outdated library (Select2 v3.5.4)
- History of high severity vulnerabilities
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) Security Vulnerabilities
CVEs by Year
Severity Breakdown
6 total CVEs
Leaflet Maps Marker <= 3.12.9 - Authenticated (Contributor+) Stored Cross-Site Scripting
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) <= 3.12.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Leaflet Maps Marker < 3.12.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) <= 3.12.4 - Authenticated (Admin+) SQL Injection
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) < 3.5.4 - Cross-Site Scripting
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) < 2.3.1 - Cross-Site Scripting
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) Attack Surface
AJAX Handlers 1
WordPress Hooks 43
Maintenance & Trust
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) Maintenance & Trust
Maintenance Signals
Community Trust
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) Alternatives
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
Ultimate Maps by Supsystic
ultimate-maps-by-supsystic
Ultimate Maps by Supsystic is the best Google Maps alternative. It includes OpenStreetMap (OSM), Bing Maps, MapBox and Thunderforest maps services
Out of the Block: OpenStreetMap
ootb-openstreetmap
A map block for Gutenberg using OpenStreetMap and Leaflet that needs no API keys and works out of the box. Or should we say, ...Out of the Block?
Map Engine – Google Maps and Open Street Maps for WordPress
map-engine
An Ultimate map tool to revolutionize your map building experience.
Easy Map – Store Locator, Google Maps, OpenStreetMap, Leaflet Map
easy-map
Create interactive maps with store locator, markers, drawings & multiple locations. Supports OpenStreetMap and Google Maps. No API key needed.
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps) Developer Profile
3 plugins · 10K total installs
How We Detect Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/leaflet-maps-marker/leaflet-maps-marker.css/wp-content/plugins/leaflet-maps-marker/leaflet-maps-marker.js/wp-content/plugins/leaflet-maps-marker/css/leaflet-maps-marker-admin.css/wp-content/plugins/leaflet-maps-marker/css/leaflet-maps-marker.css/wp-content/plugins/leaflet-maps-marker/js/leaflet-maps-marker-admin.js/wp-content/plugins/leaflet-maps-marker/js/leaflet-maps-marker.js/wp-content/plugins/leaflet-maps-marker/js/leaflet-maps-marker.min.js/wp-content/plugins/leaflet-maps-marker/js/leaflet-maps-marker-map.jsleaflet-maps-marker/leaflet-maps-marker.jsleaflet-maps-marker/leaflet-maps-marker.min.jsleaflet-maps-marker/js/leaflet-maps-marker-map.jsleaflet-maps-marker/leaflet-maps-marker.js?ver=leaflet-maps-marker/leaflet-maps-marker.min.js?ver=leaflet-maps-marker/js/leaflet-maps-marker-map.js?ver=HTML / DOM Fingerprints
leaflet-maps-markerinfo prevent file from being accessed directlyASCII Map (C) 1998 Matthew Thomas (freely usable as long as this line is included)info: die if old pro version is activeinfo: define necessary paths and urls+1 moredata-lmm-marker-iddata-lmm-map-idwindow.leaflet_maps_marker_openwindow.leaflet_maps_marker_cookie[leaflet-maps-marker]