RealTime Visitors Stats and Geolocation Security & Risk Analysis

wordpress.org/plugins/mapmyuser-widget

This Widget plugin let you inject MapmyUser.com tracking code into your Blog to enable real-time visitor tracking.

30 active installs v1.4 PHP + WP 2.8+ Updated Sep 2, 2014
analyticscounterjavascriptstatisticsstats
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is RealTime Visitors Stats and Geolocation Safe to Use in 2026?

Generally Safe

Score 85/100

RealTime Visitors Stats and Geolocation has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The mapmyuser-widget v1.4 plugin exhibits a mixed security posture. On the positive side, the plugin reports a lack of known CVEs, dangerous functions, direct SQL queries, file operations, external HTTP requests, and cron events. This suggests a generally cautious development approach regarding common attack vectors. However, significant concerns arise from the static analysis. Notably, 100% of the identified output locations are not properly escaped, representing a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. Furthermore, the taint analysis indicates two flows with unsanitized paths, although no critical or high severity issues were flagged in this area. The complete absence of capability checks and nonce checks across all entry points, coupled with a lack of authentication checks on the (albeit zero) AJAX handlers, leaves the plugin open to potential unauthorized actions if any entry points were to be developed or discovered. The vulnerability history being completely clean is a positive indicator, but it does not mitigate the risks identified in the current code analysis. A diligent approach to output escaping and input sanitization is crucial to improve its security.

Key Concerns

  • Output escaping is not implemented
  • Taint analysis shows unsanitized paths
  • Missing capability checks
  • Missing nonce checks
Vulnerabilities
None known

RealTime Visitors Stats and Geolocation Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

RealTime Visitors Stats and Geolocation Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped6 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
mapmyuser_settings_page (mapmyuser_widget.php:64)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

RealTime Visitors Stats and Geolocation Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 2
actionwp_footermapmyuser_widget.php:11
actionadmin_menumapmyuser_widget.php:12
Maintenance & Trust

RealTime Visitors Stats and Geolocation Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedSep 2, 2014
PHP min version
Downloads34K

Community Trust

Rating100/100
Number of ratings1
Active installs30
Developer Profile

RealTime Visitors Stats and Geolocation Developer Profile

sunnyverma1984

7 plugins · 270 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect RealTime Visitors Stats and Geolocation

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mapmyuser-widget/jscolor/jscolor.js
Script Paths
http://www.mapmyuser.com/mmu_hidden.jshttp://www.mapmyuser.com/mapmyuser_widget.js

HTML / DOM Fingerprints

HTML Comments
<!-- MapmyUser widget code start --><!-- MapmyUser widget code end -->
Data Attributes
data-jscolor
JS Globals
mapmyuser_widget
FAQ

Frequently Asked Questions about RealTime Visitors Stats and Geolocation