Block for Apple Maps Security & Risk Analysis

wordpress.org/plugins/maps-block-apple

An Apple Maps block for the WordPress block editor (Gutenberg).

1K active installs v1.1.5 PHP 7.4+ WP 6.6+ Updated Jan 5, 2026
apple-mapsblockmap-block
99
A · Safe
CVEs total2
Unpatched0
Last CVEDec 23, 2022
Safety Verdict

Is Block for Apple Maps Safe to Use in 2026?

Generally Safe

Score 99/100

Block for Apple Maps has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

2 known CVEsLast CVE: Dec 23, 2022Updated 4mo ago
Risk Assessment

The "maps-block-apple" plugin v1.1.5 demonstrates a generally positive security posture in its static analysis, with no identified dangerous functions, SQL queries without prepared statements, file operations, or external HTTP requests. The high percentage of properly escaped output is also a strong indicator of good coding practices. However, the complete absence of nonce checks and capability checks across all identified entry points (even though the attack surface is currently reported as zero) is a significant concern. This suggests that if any new entry points were introduced or if the current count is inaccurate, they would likely be unprotected.

The plugin's vulnerability history, with two known CVEs including a high and a medium severity, is a major red flag. The presence of 'Prototype Pollution' and 'Uncontrolled Resource Consumption' vulnerabilities in the past indicates a history of potentially serious security flaws. While there are currently no unpatched vulnerabilities, the recurring nature of these issues suggests a pattern of developing insecure code, or a failure to fully address underlying architectural weaknesses that led to these vulnerabilities. This history, combined with the lack of explicit security checks on entry points, elevates the overall risk.

In conclusion, while the static code analysis reveals some strengths, the plugin's past vulnerability history and the potential for unprotected entry points present a notable risk. The plugin has demonstrated a propensity for serious security flaws in the past, and the current lack of robust authentication and authorization mechanisms on its entry points means that any future vulnerabilities could be exploited more easily. Users should exercise caution and remain vigilant for future updates and security advisories.

Key Concerns

  • Past High Severity Vulnerability
  • Past Medium Severity Vulnerability
  • No Nonce Checks on Entry Points
  • No Capability Checks on Entry Points
  • High percentage of output unescaped
Vulnerabilities
2 published

Block for Apple Maps Security Vulnerabilities

CVEs by Year

2 CVEs in 2022
2022
Patched Has unpatched

Severity Breakdown

High
1
Medium
1

2 total CVEs

CVE-2022-46175high · 8.8Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')

json5 <= 1.0.1 and 2.0.0-2.2.1 - Prototype Pollution

Dec 23, 2022 Patched in 1.1.0 (396d)
CVE-2022-21670medium · 5.3Uncontrolled Resource Consumption

markdown-it < 1.3.2 - Uncontrolled Resource Consumption

Jan 10, 2022 Patched in 1.1.0 (743d)
Version History

Block for Apple Maps Release Timeline

v1.1.5Current
v1.1.4
v1.1.3
v1.1.2
v1.1.1
v1.1.0
Code Analysis
Analyzed Mar 16, 2026

Block for Apple Maps Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
3
32 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped35 total outputs
Attack Surface

Block for Apple Maps Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_notices10up-lib\wp-compat-validation-tool\src\Validator.php:137
actioninitincludes\block-assets.php:10
actionenqueue_block_assetsincludes\block-assets.php:81
actioninitincludes\block-assets.php:96
actionrest_api_initincludes\rest-routes.php:17
actionadmin_menuincludes\settings.php:19
actionadmin_initincludes\settings.php:20
actionadmin_initincludes\settings.php:21
actionrest_api_initincludes\settings.php:22
actionadmin_enqueue_scriptsincludes\settings.php:24
actioninitmaps-block-apple.php:43
Maintenance & Trust

Block for Apple Maps Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 5, 2026
PHP min version7.4
Downloads33K

Community Trust

Rating100/100
Number of ratings2
Active installs1K
Developer Profile

Block for Apple Maps Developer Profile

10up

23 plugins · 1.4M total installs

76
trust score
Avg Security Score
95/100
Avg Patch Time
536 days
View full developer profile
Detection Fingerprints

How We Detect Block for Apple Maps

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/maps-block-apple/assets/css/admin-maps-block-apple-settings.css/wp-content/plugins/maps-block-apple/build/admin-settings.js/wp-content/plugins/maps-block-apple/build/index.js/wp-content/plugins/maps-block-apple/build/frontend.js
Script Paths
https://cdn.apple-mapkit.com/mk/5.x.x/mapkit.js
Version Parameters
maps-block-apple/assets/css/admin-maps-block-apple-settings.css?ver=maps-block-apple/build/admin-settings.js?ver=maps-block-apple/build/index.js?ver=maps-block-apple/build/frontend.js?ver=

HTML / DOM Fingerprints

CSS Classes
maps-block-apple-settingsblock-editor-block-list__block
Data Attributes
data-maps-block-apple-settings-url
JS Globals
_mbaData
REST Endpoints
/wp-json/maps-block-apple/v1/settings
FAQ

Frequently Asked Questions about Block for Apple Maps