Mapfy Security & Risk Analysis

wordpress.org/plugins/mapfy

WordPress Google Maps Plugin

0 active installs v1.0.1 PHP 5.6+ WP 4.0+ Updated May 20, 2024
google-mapsleafletmap-blockmaps
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Mapfy Safe to Use in 2026?

Generally Safe

Score 92/100

Mapfy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The Mapfy plugin version 1.0.1 exhibits a generally good security posture based on the provided static analysis. It demonstrates a strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and properly escaping a high percentage of its output. Furthermore, the plugin implements nonce checks on all identified AJAX handlers and includes capability checks on most of them, significantly reducing the risk of unauthorized actions. The absence of known vulnerabilities in its history is a positive indicator of its current security.

However, there are a couple of areas that warrant attention. The presence of two "flows with unsanitized paths" in the taint analysis, even though categorized as critical/high severity zero, suggests potential vulnerabilities related to file path handling. While the static analysis didn't flag these as critical, it's a common area for exploits, and further investigation is recommended to ensure these paths are indeed handled securely. The existence of external HTTP requests also introduces a dependency on external services, which could become a vector if those services are compromised.

In conclusion, Mapfy v1.0.1 is a plugin with a solid security foundation, particularly in its handling of database interactions and output escaping. The primary area of concern lies in the identified unsanitized paths, which, although not currently flagged as critical, represent a latent risk. Continued vigilance and potential manual review of these specific code flows are advisable.

Key Concerns

  • Flows with unsanitized paths found
  • External HTTP requests present
Vulnerabilities
None known

Mapfy Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Mapfy Release Timeline

v1.0.1Current
Code Analysis
Analyzed Mar 17, 2026

Mapfy Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
31
155 escaped
Nonce Checks
4
Capability Checks
3
File Operations
0
External Requests
4
Bundled Libraries
0

Output Escaping

83% escaped186 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
notification_action (Inc\Classes\Notifications\Notifications.php:48)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Mapfy Attack Surface

Entry Points4
Unprotected0

AJAX Handlers 4

authwp_ajax_mapfy_deactivation_surveyInc\Classes\Feedback.php:32
authwp_ajax_mapfy_notification_actionInc\Classes\Notifications\Notifications.php:40
authwp_ajax_mapfy_subscribeInc\Classes\Notifications\Subscribe.php:26
authwp_ajax_mapfy_allow_collectInc\Classes\Notifications\What_We_Collect.php:30
WordPress Hooks 21
actionplugins_loadedclass-mapfy.php:48
filteradmin_body_classclass-mapfy.php:50
actionplugins_loadedInc\Classes\Admin.php:25
actionadmin_enqueue_scriptsInc\Classes\Feedback.php:30
actionadmin_footerInc\Classes\Feedback.php:31
actionadmin_noticesInc\Classes\Notifications\Notifications.php:35
actionmapfy_display_noticeInc\Classes\Notifications\Notifications.php:37
actionmapfy_display_popupInc\Classes\Notifications\Notifications.php:38
actionmapfy_sheet_promo_data_resetInc\Classes\Notifications\Upgrade_Notice.php:26
actionadmin_footerInc\Classes\Pro_Upgrade.php:50
actionwp_dashboard_setupInc\Classes\Pro_Upgrade.php:52
actionplugins_loadedInc\Elementor\Elementor.php:25
actionelementor/widgets/widgets_registeredInc\Elementor\Elementor.php:28
actionadmin_noticesInc\Elementor\Elementor.php:41
actionadmin_noticesInc\Elementor\Elementor.php:47
actionadmin_noticesInc\Elementor\Elementor.php:53
actionenqueue_block_editor_assetsInc\Gutenberg\Gutenberg.php:22
actioninitInc\Gutenberg\Gutenberg.php:23
actionadmin_enqueue_scriptsLibs\Assets.php:28
actionelementor/frontend/before_register_scriptsLibs\Assets.php:31
actionelementor/editor/after_enqueue_scriptsLibs\Assets.php:33
Maintenance & Trust

Mapfy Maintenance & Trust

Maintenance Signals

WordPress version tested6.4.8
Last updatedMay 20, 2024
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Mapfy Developer Profile

Pixar Labs

3 plugins · 2K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Mapfy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mapfy/assets/admin/css/mapfy-survey.css
Version Parameters
mapfy/assets/admin/css/mapfy-survey.css?ver=

HTML / DOM Fingerprints

CSS Classes
jltmapfy-deactivate-survey-overlayjltmapfy-deactivate-survey-modaljltmapfy-deactivate-survey-headerjltmapfy-deactivate-infojltmapfy-deactivate-content-wrapperjltmapfy-deactivate-form-wrapperjltmapfy-deactivate-input-wrapperjltmapfy-deactivate-feedback-dialog-input+4 more
HTML Comments
don't call the file directlyFeedbackConstruct MethodDeactivation Survey+1 more
Data Attributes
id="jltmapfy-deactivate-survey-overlay"id="jltmapfy-deactivate-survey-modal"id="jltmapfy-deactivate-feedback-no_longer_needed"name="reason_key"value="no_longer_needed"id="jltmapfy-deactivate-feedback-found_a_better_plugin"+15 more
REST Endpoints
wp_ajax_mapfy_deactivation_survey
FAQ

Frequently Asked Questions about Mapfy