
Map to Address Security & Risk Analysis
wordpress.org/plugins/map-to-addressCustomers can mark their location on google map and address will be automatically populated.
Is Map to Address Safe to Use in 2026?
Generally Safe
Score 100/100Map to Address has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "map-to-address" plugin v1.0.17 presents a mixed security posture. On the positive side, the code does not utilize dangerous functions, all SQL queries are properly prepared, and the vast majority of output is correctly escaped. There are no known vulnerabilities (CVEs) associated with this plugin, which is a strong indicator of good past security practices or a lack of public discovery. However, a significant concern arises from the plugin's attack surface. It exposes two AJAX handlers, both of which lack any authentication or capability checks. This means any user, even an unauthenticated one, could potentially interact with these endpoints, opening the door for various attacks if the handler logic is flawed or susceptible to manipulation.
The lack of taint analysis results might indicate that the tools used did not find any significant flows, or the analysis might have been limited. However, given the unprotected AJAX endpoints, the absence of taint analysis does not alleviate the risk. The direct exposure of these entry points without proper authorization is a critical weakness. While the plugin demonstrates good practices in other areas, the unprotected AJAX handlers represent a substantial security vulnerability that could be exploited to perform unauthorized actions or disrupt the site's functionality. A thorough review of the logic within these AJAX handlers is highly recommended to identify and mitigate any potential exploits.
Key Concerns
- Unprotected AJAX handlers
- No nonce checks on AJAX handlers
- Limited capability checks
Map to Address Security Vulnerabilities
Map to Address Code Analysis
Output Escaping
Map to Address Attack Surface
AJAX Handlers 2
WordPress Hooks 22
Maintenance & Trust
Map to Address Maintenance & Trust
Maintenance Signals
Community Trust
Map to Address Alternatives
WP Go Maps (formerly WP Google Maps)
wp-google-maps
The easiest to use Google maps plugin! Create a custom Google map, map block, store locator or map widget with high quality markers containing categor …
iframe
iframe
[iframe src="http://www.youtube.com/embed/7_nAZQt9qu0" width="100%" height="500"] shortcode
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
WP Store Locator
wp-store-locator
An easy to use location management system that enables users to search for nearby physical stores.
API KEY for Google Maps
api-key-for-google-maps
Retroactively add Google Maps API KEY to any theme or plugin.
Map to Address Developer Profile
12 plugins · 3K total installs
How We Detect Map to Address
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/map-to-address/admin/css/common.css/wp-content/plugins/map-to-address/admin/css/settings-sidebar.css/wp-content/plugins/map-to-address/admin/css/woocommerce-delivery-location-map-picker-admin.css/wp-content/plugins/map-to-address/admin/js/woocommerce-delivery-location-map-picker-admin.js/wp-content/plugins/map-to-address/includes/assets/css/styles.css/wp-content/plugins/map-to-address/includes/assets/js/scripts.js/wp-content/plugins/map-to-address/admin/js/woocommerce-delivery-location-map-picker-admin.js/wp-content/plugins/map-to-address/includes/assets/js/scripts.jsmap-to-address/admin/css/common.css?ver=map-to-address/admin/css/settings-sidebar.css?ver=map-to-address/admin/css/woocommerce-delivery-location-map-picker-admin.css?ver=map-to-address/admin/js/woocommerce-delivery-location-map-picker-admin.js?ver=map-to-address/includes/assets/css/styles.css?ver=map-to-address/includes/assets/js/scripts.js?ver=HTML / DOM Fingerprints
sgmta-map-wrappersgmta-address-input-wrappersgmta-map-picker-containersgmta-map-picker-mapsgmta-map-picker-controlssgmta-map-picker-address-formsgmta-map-picker-latitude-longitudesgmta-map-picker-zip-code+12 more<!-- BEGIN map-to-address SHORTCODE --><!-- END map-to-address SHORTCODE --><!-- SGMTA MAP PICKER -->data-map-iddata-latitudedata-longitudedata-address-inputdata-street-address-inputdata-address-line2-input+14 moreSGMTA_MapPickersgmta_map_data[map_to_address][delivery_map][delivery_location_map]