
Many points on the map Security & Risk Analysis
wordpress.org/plugins/many-points-on-the-mapThe plugin helps you set points on the map and filter them in the future.
Is Many points on the map Safe to Use in 2026?
Generally Safe
Score 85/100Many points on the map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "many-points-on-the-map" v1.4.1 plugin presents a generally good security posture with several positive indicators. The absence of known CVEs and a clean vulnerability history is a significant strength, suggesting a history of responsible development. The static analysis highlights a robust approach to handling SQL queries with 100% prepared statements and the presence of nonce checks for all AJAX handlers, which are crucial for preventing common attack vectors. There are also no reported file operations or external HTTP requests, further limiting the plugin's potential attack surface.
However, there are areas for concern. The most notable is the low percentage of properly escaped output (21%). This indicates a significant risk of Cross-Site Scripting (XSS) vulnerabilities, as user-supplied data or plugin-generated content may not be properly sanitized before being displayed to users. While the taint analysis shows only one flow with an unsanitized path and no critical or high severity issues, the lack of output escaping makes this flow potentially more dangerous. Furthermore, the complete absence of capability checks is a weakness, meaning that actions performed by the plugin might not be restricted to authorized users, although the static analysis doesn't explicitly state these actions are directly exposed.
In conclusion, while the plugin benefits from a lack of historical vulnerabilities and strong practices around SQL and AJAX security, the widespread lack of output escaping and missing capability checks represent significant risks that should be addressed to improve its overall security. The plugin's low attack surface and absence of dangerous functions are positive, but the identified weaknesses could still lead to security incidents.
Key Concerns
- Low percentage of properly escaped output
- No capability checks found
- One flow with unsanitized path
Many points on the map Security Vulnerabilities
Many points on the map Release Timeline
Many points on the map Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Many points on the map Attack Surface
AJAX Handlers 6
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Many points on the map Maintenance & Trust
Maintenance Signals
Community Trust
Many points on the map Alternatives
WP Go Maps (formerly WP Google Maps)
wp-google-maps
The easiest to use Google maps plugin! Create a custom Google map, map block, store locator or map widget with high quality markers containing categor …
iframe
iframe
[iframe src="http://www.youtube.com/embed/7_nAZQt9qu0" width="100%" height="500"] shortcode
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
WP Store Locator
wp-store-locator
An easy to use location management system that enables users to search for nearby physical stores.
API KEY for Google Maps
api-key-for-google-maps
Retroactively add Google Maps API KEY to any theme or plugin.
Many points on the map Developer Profile
12 plugins · 1K total installs
How We Detect Many points on the map
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/many-points-on-the-map/includes/admin/assets/js/custom.js/wp-content/plugins/many-points-on-the-map/includes/admin/assets/bootstrap-4.1.1/css/bootstrap.min.css/wp-content/plugins/many-points-on-the-map/assets/font-awesome-4.6.3/css/font-awesome.min.css/wp-content/plugins/many-points-on-the-map/includes/admin/assets/css/style.css/wp-content/plugins/many-points-on-the-map/includes/admin/assets/js/script.js/wp-content/plugins/many-points-on-the-map/includes/admin/assets/js/custom.js/wp-content/plugins/many-points-on-the-map/includes/admin/assets/js/script.jsmany-points-on-the-map/includes/admin/assets/js/custom.js?ver=many-points-on-the-map/includes/admin/assets/bootstrap-4.1.1/css/bootstrap.min.css?ver=many-points-on-the-map/assets/font-awesome-4.6.3/css/font-awesome.min.css?ver=many-points-on-the-map/includes/admin/assets/css/style.css?ver=many-points-on-the-map/includes/admin/assets/js/script.js?ver=HTML / DOM Fingerprints
mxmpotm_notification_markermxmpotm_notification_alphabet_ordermxmpotm_localize_script_custom_objmxmpotm_localize_script_obj