Map Block Leaflet Security & Risk Analysis

wordpress.org/plugins/map-block-leaflet

Embed maps in content without needing to include an API key.

700 active installs v3.2.2 PHP + WP 5.0+ Updated May 28, 2025
blockseditorgutenbergleafletmap
99
A · Safe
CVEs total1
Unpatched0
Last CVEMay 28, 2025
Download
Safety Verdict

Is Map Block Leaflet Safe to Use in 2026?

Generally Safe

Score 99/100

Map Block Leaflet has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: May 28, 2025Updated 10mo ago
Risk Assessment

The static analysis of map-block-leaflet v3.2.2 reveals a generally positive security posture, with no detected dangerous functions, file operations, external HTTP requests, or unescaped output. SQL queries are exclusively handled with prepared statements. The attack surface is reported as zero entry points, and taint analysis shows no flows with unsanitized paths, indicating robust handling of potential input vulnerabilities within the code's current state.

Despite the strong static analysis, the plugin has a history of one medium-severity Cross-Site Scripting (XSS) vulnerability, which was last patched on 2025-05-28. While there are no currently unpatched vulnerabilities, this past incident highlights a potential area of concern and suggests that developers should remain vigilant about input sanitization, especially in areas not covered by the current static analysis.

In conclusion, the plugin demonstrates good development practices in its current version, with no immediate critical or high risks identified in the code. However, the historical XSS vulnerability, even if patched, warrants a slight reduction in confidence due to the potential for similar issues to arise if not continually monitored. The lack of explicit capability or nonce checks, while not flagged as an issue in this specific analysis, could be a consideration for future hardening, particularly if any new entry points are introduced.

Key Concerns

  • Past medium severity XSS vulnerability
  • No nonce checks present
  • No capability checks present
Vulnerabilities
1

Map Block Leaflet Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-5122medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Map Block Leaflet <= 3.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting via url Parameter

May 28, 2025 Patched in 3.2.2 (1d)
Code Analysis
Analyzed Mar 16, 2026

Map Block Leaflet Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Map Block Leaflet Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitmap-block-leaflet.php:39
Maintenance & Trust

Map Block Leaflet Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 28, 2025
PHP min version
Downloads15K

Community Trust

Rating100/100
Number of ratings9
Active installs700
Developer Profile

Map Block Leaflet Developer Profile

goiblas

4 plugins · 1K total installs

97
trust score
Avg Security Score
96/100
Avg Patch Time
1 days
View full developer profile
Detection Fingerprints

How We Detect Map Block Leaflet

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/map-block-leaflet/build/leaflet-map-block/wp-content/plugins/map-block-leaflet/build/multi-marker
Script Paths
/wp-content/plugins/map-block-leaflet/lib/leaflet.js
Version Parameters
plugins_url($lib_style_path, __FILE__), array(), $lib_versionplugins_url($lib_script_path, __FILE__), array(), $lib_version, false

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Map Block Leaflet