
Map My Posts Security & Risk Analysis
wordpress.org/plugins/map-my-postsMap My Posts allows you to display a Google Map or Geochart visualization, associating map locations with your existing categories or tags.
Is Map My Posts Safe to Use in 2026?
Generally Safe
Score 85/100Map My Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "map-my-posts" plugin version 1.0.6 exhibits a mixed security posture. On the positive side, it has no known vulnerabilities (CVEs) and the static analysis shows no dangerous functions, no raw SQL queries, and no external HTTP requests. The attack surface is limited to three shortcodes, with no immediately apparent unprotected entry points, which is a good sign. However, there are notable areas for concern. A significant portion (59%) of the plugin's outputs are not properly escaped, posing a potential risk of Cross-Site Scripting (XSS) vulnerabilities, especially if user-supplied data is involved in these outputs. The taint analysis reveals two flows with unsanitized paths, which, while not classified as critical or high severity in this analysis, represent potential injection vectors that require careful review. Furthermore, the absence of any nonce checks and capability checks across all entry points is a critical oversight, leaving the plugin vulnerable to various forms of exploitation if any of the shortcodes can be triggered in a way that allows for unauthorized actions or data manipulation. The lack of vulnerability history might indicate good past development, but it doesn't negate the current code-level risks.
Key Concerns
- Significant unescaped output (59%)
- Taint flows with unsanitized paths (2)
- No nonce checks on entry points
- No capability checks on entry points
Map My Posts Security Vulnerabilities
Map My Posts Release Timeline
Map My Posts Code Analysis
Output Escaping
Data Flow Analysis
Map My Posts Attack Surface
Shortcodes 3
WordPress Hooks 19
Maintenance & Trust
Map My Posts Maintenance & Trust
Maintenance Signals
Community Trust
Map My Posts Alternatives
Geo Mashup
geo-mashup
Include Google and OpenStreetMap maps in posts and pages, and map posts, pages, and other objects on global maps. Make WordPress into a GeoCMS.
Basic Google Maps Placemarks
basic-google-maps-placemarks
Embeds a Google Map into your site and lets you add map markers with custom icons and information windows.
Pronamic Google Maps
pronamic-google-maps
This plugin makes it easy to add Google Maps to your WordPress post, pages or other custom post types.
Track Geolocation Of Users Using Contact Form 7
track-geolocation-of-users-using-contact-form-7
Track Geolocation Of Users Using Contact Form 7 allows you to get geolocation information with their form submission.
MapifyLite (by MapifyPro)
mapifylite
MapifyLite is an elite plugin for WordPress that implements fully-customized maps on your site.
Map My Posts Developer Profile
1 plugin · 200 total installs
How We Detect Map My Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/map-my-posts/css/map-my-posts.css/wp-content/plugins/map-my-posts/js/map-my-posts.js/wp-content/plugins/map-my-posts/js/mmp_geochart.js/wp-content/plugins/map-my-posts/js/mmp_map.js/wp-content/plugins/map-my-posts/js/mmp_staticmap.jshttps://maps.googleapis.com/maps/api/jsmap-my-posts/css/map-my-posts.css?ver=map-my-posts/js/map-my-posts.js?ver=map-my-posts/js/mmp_geochart.js?ver=map-my-posts/js/mmp_map.js?ver=map-my-posts/js/mmp_staticmap.js?ver=HTML / DOM Fingerprints
mmp_geochart_containermmp_map_containermmp_staticmap_container<!-- Map My Posts -->data-maptypedata-widthdata-heightdata-markercolordata-markersizedata-taxonomy+11 moregoogle[mmp-geochart[mmp-staticmap[mmp-map