
Listdom KML Addon – Display KML Layers Security & Risk Analysis
wordpress.org/plugins/listdom-kmlEasily add KML (and GPX) map layers to your Listdom directory maps, highlighting specific areas, routes, or boundaries.
Is Listdom KML Addon – Display KML Layers Safe to Use in 2026?
Generally Safe
Score 100/100Listdom KML Addon – Display KML Layers has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of listdom-kml v2.2.0 appears to be strong based on the provided static analysis and vulnerability history. The plugin exhibits excellent adherence to secure coding practices, with no observed dangerous functions, file operations, or external HTTP requests. Crucially, all observed output is properly escaped, and the absence of any taint flows suggests a low risk of injection vulnerabilities. The attack surface is also minimal, with no identified entry points that are exposed without authentication checks.
However, the analysis does highlight some areas that warrant attention. The presence of a SQL query that does not utilize prepared statements represents a potential risk, albeit mitigated by the fact that it is the only query and the overall attack surface is small. Furthermore, the complete lack of nonce checks and capability checks across all identified entry points (even though there are none reported) is a concerning pattern. While currently not exploitable due to the zero entry points, it indicates a potential gap in defensive programming that could become a vulnerability if new features are added without proper security considerations.
The plugin's vulnerability history is spotless, with no known CVEs ever recorded. This, combined with the clean code signals, suggests a developer who is either very diligent or has built a simple enough plugin that it hasn't attracted significant security scrutiny. Despite the lack of specific vulnerabilities, the absence of fundamental security checks like nonces and capability checks on potential future entry points represents a weakness in its defensive design, even if the attack surface is currently zero.
Key Concerns
- Raw SQL query without prepared statements
- Lack of nonce checks on potential entry points
- Lack of capability checks on potential entry points
Listdom KML Addon – Display KML Layers Security Vulnerabilities
Listdom KML Addon – Display KML Layers Code Analysis
SQL Query Safety
Output Escaping
Listdom KML Addon – Display KML Layers Attack Surface
WordPress Hooks 2
Maintenance & Trust
Listdom KML Addon – Display KML Layers Maintenance & Trust
Maintenance Signals
Community Trust
Listdom KML Addon – Display KML Layers Alternatives
OSM – OpenStreetMap
osm
Customize maps in your post, pages and widgets. GPX, KML and more. The easy way to map!
Flexible Map
wp-flexible-map
Embed Google Maps shortcodes in pages and posts, either by center coordinates or street address, or by URL to a Google Earth KML file.
Gpx2Graphics
gpx2graphics
Create a Google Map, Elevation image or Speed image from your (Garmin) GpX files.
WP Go Maps (formerly WP Google Maps)
wp-google-maps
The easiest to use Google maps plugin! Create a custom Google map, map block, store locator or map widget with high quality markers containing categor …
iframe
iframe
[iframe src="http://www.youtube.com/embed/7_nAZQt9qu0" width="100%" height="500"] shortcode
Listdom KML Addon – Display KML Layers Developer Profile
7 plugins · 2K total installs
How We Detect Listdom KML Addon – Display KML Layers
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/listdom-kml/dist/css/lsd-kml.css/wp-content/plugins/listdom-kml/dist/js/lsd-kml.js/wp-content/plugins/listdom-kml/dist/js/lsd-kml.jslistdom-kml/dist/css/lsd-kml.css?ver=listdom-kml/dist/js/lsd-kml.js?ver=HTML / DOM Fingerprints
LSD_ADDKML