Localizaciones Fotografía Security & Risk Analysis

wordpress.org/plugins/localizaciones-fotografia

Inserta en tu web un mapa todas las localizaciones que tengas subidas en www.subexpuesta.com

10 active installs v0.1 PHP + WP 3.0.1+ Updated Unknown
fotografialocalizacionesmapamapa-con-localizacionessubexpuesta
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Localizaciones Fotografía Safe to Use in 2026?

Generally Safe

Score 100/100

Localizaciones Fotografía has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "localizaciones-fotografia" plugin version 0.1 exhibits a strong security posture in several key areas, particularly concerning the absence of known vulnerabilities and a complete lack of critical or high-severity taint flows. The static analysis indicates a disciplined approach to SQL queries, with 100% using prepared statements, which is a significant strength against injection attacks. Additionally, the plugin has a relatively low number of external HTTP requests and file operations, minimizing potential attack vectors.

However, several concerning aspects warrant attention. The complete absence of nonce checks and capability checks on any identified entry points, despite the presence of file operations and external HTTP requests, creates a significant risk. Any of these operations, if triggered maliciously without proper authorization, could lead to unintended consequences. While the output escaping rate is high (81%), the remaining unescaped outputs could still be a vector for cross-site scripting (XSS) vulnerabilities, especially if they handle user-supplied data.

The plugin's vulnerability history being entirely clear is a positive indicator, suggesting either a history of secure development or a lack of historical scrutiny. Given the current static analysis findings, especially the lack of authorization checks, this positive history might be more a reflection of its limited exposure or attack surface rather than inherent robustness against all potential threats. The focus should be on addressing the identified weaknesses in authorization and output sanitization to strengthen its overall security.

Key Concerns

  • No nonce checks on entry points
  • No capability checks on entry points
  • Unescaped output found
Vulnerabilities
None known

Localizaciones Fotografía Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Localizaciones Fotografía Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
22 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
3
Bundled Libraries
0

Output Escaping

81% escaped27 total outputs
Attack Surface

Localizaciones Fotografía Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionadmin_initlocalizaciones-fotografia.php:154
Maintenance & Trust

Localizaciones Fotografía Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Localizaciones Fotografía Developer Profile

subexpuestaweb

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Localizaciones Fotografía

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/localizaciones-fotografia/class.MapBuilder.php

HTML / DOM Fingerprints

CSS Classes
firstHeading
Data Attributes
data-plugin-name="Subexpuesta"data-plugin-version="0.1"
JS Globals
Subexpuesta
REST Endpoints
/wp-json/subexpuesta/v1/localizaciones//wp-json/subexpuesta/v1/localizaciones/autor/
Shortcode Output
<p>pruebaParametros</p><p>height:</p><p>width:
FAQ

Frequently Asked Questions about Localizaciones Fotografía