
LocalPoint Security & Risk Analysis
wordpress.org/plugins/localpointDisplay your business location, opening hours and contact info using OpenStreetMap and Leaflet.js.
Is LocalPoint Safe to Use in 2026?
Generally Safe
Score 100/100LocalPoint has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'localpoint' plugin version 2.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. The absence of dangerous functions, raw SQL queries, file operations, and external HTTP requests are excellent indicators of secure coding practices. The plugin also demonstrates good adherence to WordPress security standards with the presence of nonce and capability checks, and a significant majority of its outputs being properly escaped. The attack surface is minimal, consisting of a single shortcode, and critically, there are no unprotected entry points identified. The vulnerability history further reinforces this positive outlook, with no known CVEs recorded, suggesting a history of secure development and maintenance. While the taint analysis shows no flows, which is a positive sign, it also indicates that the analysis might not have covered all potential execution paths or that the plugin's complexity is very low. The main area for potential concern, though minor given the overall findings, is the 64% proper output escaping rate, which means a portion of outputs are not escaped, introducing a theoretical risk of cross-site scripting (XSS) if those unescaped outputs were to ever become user-influenced. However, without any identified taint flows or specific vulnerabilities, this risk appears to be very low in practice.
Key Concerns
- Outputs not properly escaped
LocalPoint Security Vulnerabilities
LocalPoint Code Analysis
Output Escaping
LocalPoint Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
LocalPoint Maintenance & Trust
Maintenance Signals
Community Trust
LocalPoint Alternatives
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
Leaflet Map
leaflet-map
Interactive maps and markers on your posts and pages with simple shortcodes.
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)
leaflet-maps-marker
The most comprehensive & user-friendly mapping solution for WordPress
OSM – OpenStreetMap
osm
Customize maps in your post, pages and widgets. GPX, KML and more. The easy way to map!
Ultimate Maps by Supsystic
ultimate-maps-by-supsystic
Ultimate Maps by Supsystic is the best Google Maps alternative. It includes OpenStreetMap (OSM), Bing Maps, MapBox and Thunderforest maps services
LocalPoint Developer Profile
1 plugin · 0 total installs
How We Detect LocalPoint
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/localpoint/assets/css/leaflet.css/wp-content/plugins/localpoint/assets/js/leaflet.js/wp-content/plugins/localpoint/assets/css/style.css/wp-content/plugins/localpoint/assets/js/map.js/wp-content/plugins/localpoint/assets/js/admin-map.js/wp-content/plugins/localpoint/assets/js/leaflet.js/wp-content/plugins/localpoint/assets/js/map.js/wp-content/plugins/localpoint/assets/js/admin-map.jsver=2.0HTML / DOM Fingerprints
localpoint-maplocalpoint-infolocalpointData<div id="localpoint-map"></div><div id="localpoint-info">