
Mapfy Security & Risk Analysis
wordpress.org/plugins/mapfyWordPress Google Maps Plugin
Is Mapfy Safe to Use in 2026?
Generally Safe
Score 92/100Mapfy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The Mapfy plugin version 1.0.1 exhibits a generally good security posture based on the provided static analysis. It demonstrates a strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and properly escaping a high percentage of its output. Furthermore, the plugin implements nonce checks on all identified AJAX handlers and includes capability checks on most of them, significantly reducing the risk of unauthorized actions. The absence of known vulnerabilities in its history is a positive indicator of its current security.
However, there are a couple of areas that warrant attention. The presence of two "flows with unsanitized paths" in the taint analysis, even though categorized as critical/high severity zero, suggests potential vulnerabilities related to file path handling. While the static analysis didn't flag these as critical, it's a common area for exploits, and further investigation is recommended to ensure these paths are indeed handled securely. The existence of external HTTP requests also introduces a dependency on external services, which could become a vector if those services are compromised.
In conclusion, Mapfy v1.0.1 is a plugin with a solid security foundation, particularly in its handling of database interactions and output escaping. The primary area of concern lies in the identified unsanitized paths, which, although not currently flagged as critical, represent a latent risk. Continued vigilance and potential manual review of these specific code flows are advisable.
Key Concerns
- Flows with unsanitized paths found
- External HTTP requests present
Mapfy Security Vulnerabilities
Mapfy Release Timeline
Mapfy Code Analysis
Output Escaping
Data Flow Analysis
Mapfy Attack Surface
AJAX Handlers 4
WordPress Hooks 21
Maintenance & Trust
Mapfy Maintenance & Trust
Maintenance Signals
Community Trust
Mapfy Alternatives
MapPress Maps for WordPress
mappress-google-maps-for-wordpress
MapPress is the easiest way to add unlimited interactive Google and Leaflet maps to WordPress.
Map Block for Google Maps
map-block-gutenberg
Map block for Gutenberg editor powered by Google Maps. Simple. Fast. Just a map block.
WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map by aBlocks
wp-map-block
No API key is required to launch Google Maps & OpenStreetMap.
WP Go Maps Block
wp-go-maps-block
The easiest-to-use Google Maps plugin is now available as a standalone map block! Create custom Google maps or OpenLayers maps with high-quality marke …
Out of the Block: OpenStreetMap
ootb-openstreetmap
A map block for Gutenberg using OpenStreetMap and Leaflet that needs no API keys and works out of the box. Or should we say, ...Out of the Block?
Mapfy Developer Profile
3 plugins · 2K total installs
How We Detect Mapfy
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mapfy/assets/admin/css/mapfy-survey.cssmapfy/assets/admin/css/mapfy-survey.css?ver=HTML / DOM Fingerprints
jltmapfy-deactivate-survey-overlayjltmapfy-deactivate-survey-modaljltmapfy-deactivate-survey-headerjltmapfy-deactivate-infojltmapfy-deactivate-content-wrapperjltmapfy-deactivate-form-wrapperjltmapfy-deactivate-input-wrapperjltmapfy-deactivate-feedback-dialog-input+4 more don't call the file directlyFeedbackConstruct MethodDeactivation Survey+1 moreid="jltmapfy-deactivate-survey-overlay"id="jltmapfy-deactivate-survey-modal"id="jltmapfy-deactivate-feedback-no_longer_needed"name="reason_key"value="no_longer_needed"id="jltmapfy-deactivate-feedback-found_a_better_plugin"+15 morewp_ajax_mapfy_deactivation_survey