Lite Google Map Security & Risk Analysis

wordpress.org/plugins/lite-google-map

Lite Google Map is a lite weight maps plugins.

10 active installs v1.2 PHP + WP 3.0.1+ Updated Unknown
contact-mapgmapgoogle-mapmap
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Lite Google Map Safe to Use in 2026?

Generally Safe

Score 100/100

Lite Google Map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'lite-google-map' v1.2 plugin exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests is a strong positive indicator. Furthermore, the presence of nonce and capability checks on all identified entry points (AJAX handlers and shortcodes) significantly reduces the risk of unauthorized actions. The plugin also appears to have a clean vulnerability history with no recorded CVEs, suggesting a history of secure development or diligent patching by users.

However, a significant concern arises from the output escaping. With 68% of outputs properly escaped out of 147 total, there remains a substantial portion (32%) that is not adequately sanitized. This leaves the plugin vulnerable to cross-site scripting (XSS) attacks if user-supplied data is included in these unescaped outputs. While taint analysis showed no critical or high severity flows, this does not negate the risk presented by the unescaped outputs, as such flows might not have been detected or could be triggered under specific conditions not covered by the static analysis.

In conclusion, while the plugin demonstrates strong adherence to many security best practices, the unescaped output is a notable weakness that needs immediate attention. The lack of historical vulnerabilities is a positive sign, but it should not lead to complacency, especially given the identified output sanitation issue. Addressing the unescaped outputs would significantly improve the plugin's overall security.

Key Concerns

  • Insufficient output escaping
Vulnerabilities
None known

Lite Google Map Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Lite Google Map Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
47
100 escaped
Nonce Checks
3
Capability Checks
6
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

68% escaped147 total outputs
Attack Surface

Lite Google Map Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

authwp_ajax_cmb2_oembed_handlerinc\helper\cmb2\includes\CMB2_Ajax.php:51
noprivwp_ajax_cmb2_oembed_handlerinc\helper\cmb2\includes\CMB2_Ajax.php:52

Shortcodes 1

[google_maps] map-functions.php:180
WordPress Hooks 38
actioncmb2_render_radio_imageinc\cmb2-radio-image.php:19
filtercmb2_list_input_attributesinc\cmb2-radio-image.php:20
actionadmin_headinc\cmb2-radio-image.php:21
filterwp_prepare_attachment_for_jsinc\helper\cmb2\includes\CMB2.php:1399
actioncmb2_save_options-page_fieldsinc\helper\cmb2\includes\CMB2_Ajax.php:54
filterget_post_metadatainc\helper\cmb2\includes\CMB2_Ajax.php:147
filterupdate_post_metadatainc\helper\cmb2\includes\CMB2_Ajax.php:150
filtercmb2_show_oninc\helper\cmb2\includes\CMB2_hookup.php:69
actionedit_form_topinc\helper\cmb2\includes\CMB2_hookup.php:103
actionedit_form_before_permalinkinc\helper\cmb2\includes\CMB2_hookup.php:107
actionedit_form_after_titleinc\helper\cmb2\includes\CMB2_hookup.php:111
actionedit_form_after_editorinc\helper\cmb2\includes\CMB2_hookup.php:115
actionadd_meta_boxesinc\helper\cmb2\includes\CMB2_hookup.php:119
actionadd_attachmentinc\helper\cmb2\includes\CMB2_hookup.php:122
actionedit_attachmentinc\helper\cmb2\includes\CMB2_hookup.php:123
actionsave_postinc\helper\cmb2\includes\CMB2_hookup.php:124
actionadd_meta_boxes_commentinc\helper\cmb2\includes\CMB2_hookup.php:135
actionedit_commentinc\helper\cmb2\includes\CMB2_hookup.php:136
filtermanage_edit-comments_columnsinc\helper\cmb2\includes\CMB2_hookup.php:139
actionmanage_comments_custom_columninc\helper\cmb2\includes\CMB2_hookup.php:140
actionshow_user_profileinc\helper\cmb2\includes\CMB2_hookup.php:147
actionedit_user_profileinc\helper\cmb2\includes\CMB2_hookup.php:148
actionuser_new_forminc\helper\cmb2\includes\CMB2_hookup.php:149
actionpersonal_options_updateinc\helper\cmb2\includes\CMB2_hookup.php:151
actionedit_user_profile_updateinc\helper\cmb2\includes\CMB2_hookup.php:152
actionuser_registerinc\helper\cmb2\includes\CMB2_hookup.php:153
filtermanage_users_columnsinc\helper\cmb2\includes\CMB2_hookup.php:156
filtermanage_users_custom_columninc\helper\cmb2\includes\CMB2_hookup.php:157
actioncreated_terminc\helper\cmb2\includes\CMB2_hookup.php:203
actionedited_termsinc\helper\cmb2\includes\CMB2_hookup.php:204
actiondelete_terminc\helper\cmb2\includes\CMB2_hookup.php:205
actioncmb2_do_oembedinc\helper\cmb2\includes\helper-functions.php:127
filteris_protected_metainc\helper\cmb2\includes\rest-api\CMB2_REST.php:124
actioninitinc\helper\cmb2\init.php:81
actioncmb2_admin_initinc\settings.php:68
actionwp_enqueue_scriptsmap-functions.php:20
actionwp_footermap-functions.php:159
actionadmin_enqueue_scriptsmap-functions.php:186
Maintenance & Trust

Lite Google Map Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedUnknown
PHP min version
Downloads1K

Community Trust

Rating100/100
Number of ratings2
Active installs10
Developer Profile

Lite Google Map Developer Profile

B.M. Rafiul Alam

4 plugins · 7K total installs

96
trust score
Avg Security Score
94/100
Avg Patch Time
3 days
View full developer profile
Detection Fingerprints

How We Detect Lite Google Map

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/lite-google-map/css/map.css/wp-content/plugins/lite-google-map/js/marker.js/wp-content/plugins/lite-google-map/js/map.js/wp-content/plugins/lite-google-map/js/infobox.js/wp-content/plugins/lite-google-map/js/infobox.js.map/wp-content/plugins/lite-google-map/js/marker.js.map/wp-content/plugins/lite-google-map/js/map.js.map
Script Paths
/wp-content/plugins/lite-google-map/js/map.js/wp-content/plugins/lite-google-map/js/marker.js/wp-content/plugins/lite-google-map/js/infobox.js
Version Parameters
lite-google-map/css/map.css?ver=lite-google-map/js/marker.js?ver=lite-google-map/js/map.js?ver=lite-google-map/js/infobox.js?ver=

HTML / DOM Fingerprints

CSS Classes
lite-google-map
Shortcode Output
[lite_google_map]
FAQ

Frequently Asked Questions about Lite Google Map