
Map Navigator Security & Risk Analysis
wordpress.org/plugins/mapnavigatorCreate Posts for Map Navigation for a geographical taxonomy using MapPress Google Maps in WordPress.
Is Map Navigator Safe to Use in 2026?
Generally Safe
Score 85/100Map Navigator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The mapnavigator plugin version 1.1.0 exhibits a concerning security posture due to significant vulnerabilities identified in the static analysis. A major red flag is the presence of three AJAX handlers that lack authentication checks, creating a substantial attack surface. Furthermore, the taint analysis revealed three high-severity flows with unsanitized paths, indicating potential for attackers to inject malicious data. The plugin also heavily relies on dangerous functions like `unserialize` and `create_function`, which are often associated with security risks if not handled with extreme care. The output escaping is also alarmingly poor, with only 5% of outputs properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities.
While the plugin has no recorded CVEs, this historical absence of public vulnerabilities should not be interpreted as a sign of robust security, especially given the critical findings in the static analysis. The low percentage of prepared SQL statements (81%) also presents a risk of SQL injection, although less severe than the other identified issues. The lack of nonce checks on AJAX endpoints is another critical oversight. The plugin's strength lies in its clean vulnerability history and absence of bundled libraries, but these are overshadowed by the severe security flaws present in its current version.
Key Concerns
- AJAX handlers without auth checks
- High severity unsanitized taint flows
- Use of dangerous functions (unserialize, create_function)
- Low percentage of properly escaped output
- Low percentage of prepared SQL statements
- No nonce checks on AJAX
Map Navigator Security Vulnerabilities
Map Navigator Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Map Navigator Attack Surface
AJAX Handlers 3
Shortcodes 2
WordPress Hooks 95
Maintenance & Trust
Map Navigator Maintenance & Trust
Maintenance Signals
Community Trust
Map Navigator Alternatives
CSV Importer Improved
csv-importer-improved
Import posts from CSV files into WordPress.
CSV Importer
csv-importer
Import posts from CSV files into WordPress.
Post Importer for Excel
post-importer-for-excel
Effortlessly create hundreds of WordPress posts in minutes by uploading a CSV or Excel file.
TablePress – Tables in WordPress made easy
tablepress
Embed beautiful, accessible, and interactive tables into your WordPress website’s posts and pages, without having to write code!
Spreadsheet Price Changer for WooCommerce and WP E-commerce – Light
excel-like-price-change-for-woocommerce-and-wp-e-commerce-light
Spreadsheet Price Changer for WooCommerce and WP E-commerce - Light
Map Navigator Developer Profile
1 plugin · 10 total installs
How We Detect Map Navigator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mapnavigator/css/mapnavigator.css/wp-content/plugins/mapnavigator/js/mapnavigator.js/wp-content/plugins/mapnavigator/js/mapnavigator.jsmapnavigator/css/mapnavigator.css?ver=mapnavigator/js/mapnavigator.js?ver=HTML / DOM Fingerprints
name="nav_importer_organization_name"name="nav_importer_organization_image"name="nav_importer_organization_web_link"name="map_icon"