
Mapoza Click-to-Load for Google Maps Security & Risk Analysis
wordpress.org/plugins/mapoza-click-to-load-for-google-mapsLoad Google Maps embeds only after a visitor clicks, improving privacy and performance.
Is Mapoza Click-to-Load for Google Maps Safe to Use in 2026?
Generally Safe
Score 100/100Mapoza Click-to-Load for Google Maps has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'mapoza-click-to-load-for-google-maps' version 1.0.0 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code shows excellent adherence to secure coding practices, with 100% of SQL queries using prepared statements and all output being properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further bolsters its security. The limited attack surface, consisting of a single shortcode, with no identified AJAX handlers or REST API routes lacking permission callbacks, is also a positive indicator.
The vulnerability history is completely clean, with no known CVEs, critical or otherwise. This lack of historical vulnerabilities suggests a well-maintained and tested codebase. The absence of any taint analysis findings, particularly for critical or high severity issues, reinforces the impression of secure code. The only potential, albeit minor, point of consideration is the absence of nonce checks. While the current attack surface is minimal and protected by capability checks, as the plugin evolves and potentially introduces new entry points or functionality, implementing nonce checks would be a proactive security measure.
Overall, this plugin appears to be very secure in its current state. The developers have demonstrated a commitment to secure coding practices, and the lack of any reported vulnerabilities is highly reassuring. The only area for potential improvement would be the addition of nonce checks if the plugin were to expand its feature set, but for version 1.0.0, the security is commendable.
Key Concerns
- Missing nonce checks
Mapoza Click-to-Load for Google Maps Security Vulnerabilities
Mapoza Click-to-Load for Google Maps Release Timeline
Mapoza Click-to-Load for Google Maps Code Analysis
Output Escaping
Mapoza Click-to-Load for Google Maps Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Mapoza Click-to-Load for Google Maps Maintenance & Trust
Maintenance Signals
Community Trust
Mapoza Click-to-Load for Google Maps Alternatives
WP YouTube Lyte
wp-youtube-lyte
High performance YouTube video, playlist and audio-only embeds which don't slow down your blog and offer optimal accessibility.
Lazy Load for Videos
lazy-load-for-videos
Boost page speed by replacing embedded YouTube and Vimeo videos with a clickable preview image. Video scripts only load on click.
Lazy Load for GMaps
lazy-load-for-gmaps
Short Description: Simple WordPress plugin that loads Google Maps in posts and pages via Lazy Load for faster page performance.
GDPR Compliant Google Maps
gdpr-compliant-google-maps
A simple, GDPR-compliant Google Maps plugin that requires user consent before displaying maps.
Complianz – GDPR/CCPA Cookie Consent
complianz-gdpr
Configure your Cookie Banner, Cookie Consent and Cookie Policy with our Wizard and Cookies Scan.
Mapoza Click-to-Load for Google Maps Developer Profile
1 plugin · 0 total installs
How We Detect Mapoza Click-to-Load for Google Maps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mapoza-click-to-load-for-google-maps/assets/css/frontend.css/wp-content/plugins/mapoza-click-to-load-for-google-maps/assets/js/frontend.js/wp-content/plugins/mapoza-click-to-load-for-google-maps/assets/js/frontend.jsmapoza-click-to-load-for-google-maps/assets/css/frontend.css?ver=mapoza-click-to-load-for-google-maps/assets/js/frontend.js?ver=HTML / DOM Fingerprints
mapoza-ctlgm-mapmapoza-ctlgm-map__placeholdermapoza-ctlgm-map__contentmapoza-ctlgm-map__messagemapoza-ctlgm-map__buttondata-embed-urldata-titlestyle="--mapoza-ctlgm-map-height:[mapoza_ctlgm_google_map]