MapSwap for The Events Calendar Security & Risk Analysis

wordpress.org/plugins/mapswap-for-the-events-calendar

MapSwap for The Events Calendar replaces Google Maps with an alternative map provider on the single event pages.

10 active installs v1.1.1 PHP 8.0+ WP 6.7+ Updated May 6, 2026
calendareventsmapopenstreetmap
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is MapSwap for The Events Calendar Safe to Use in 2026?

Generally Safe

Score 100/100

MapSwap for The Events Calendar has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The plugin "mapswap-for-the-events-calendar" v1.0.0 exhibits a seemingly strong security posture based on the provided static analysis and vulnerability history. The absence of identified AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code analysis shows no dangerous functions, no unescaped outputs, no file operations, no external HTTP requests, and no taint flows of any severity. The fact that all SQL queries use prepared statements is a positive indicator of secure database interaction.

However, the lack of any identified entry points in the static analysis might indicate incomplete analysis or a very rudimentary plugin. More importantly, the absence of nonce checks and capability checks across the board, despite there being no explicitly identified entry points, is a significant concern. While the current version might not have exploitable vulnerabilities, this lack of fundamental security checks creates a significant risk should any new entry points be added or discovered in the future, or if the initial analysis was insufficient. The clean vulnerability history is positive, suggesting developers have historically been mindful of security, but it does not mitigate the risks posed by the current implementation's weaknesses.

In conclusion, while the plugin currently appears to have no known vulnerabilities and demonstrates good practices in specific areas like SQL query handling, the complete absence of nonce and capability checks represents a foundational security weakness. This makes the plugin susceptible to privilege escalation and cross-site request forgery if any form of interaction is introduced or overlooked in the future. The plugin's strengths lie in its clean code regarding dangerous functions and SQL, but its weaknesses in authorization and input validation (implied by lack of checks) are notable.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
  • Unescaped output found
Vulnerabilities
None known

MapSwap for The Events Calendar Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

MapSwap for The Events Calendar Release Timeline

v1.1.1Current
v1.1.0
v1.0.0
Code Analysis
Analyzed Mar 17, 2026

MapSwap for The Events Calendar Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

50% escaped2 total outputs
Attack Surface

MapSwap for The Events Calendar Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 4
actionplugins_loadedmapswap-for-the-events-calendar.php:25
actioninitsrc\MapSwap_For_TEC\Main.php:18
filtertribe_get_map_link_htmlsrc\MapSwap_For_TEC\Main.php:20
filtertec_events_settings_display_maps_sectionsrc\MapSwap_For_TEC\Settings.php:33
Maintenance & Trust

MapSwap for The Events Calendar Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.5
Last updatedMay 6, 2026
PHP min version8.0
Downloads622

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

MapSwap for The Events Calendar Developer Profile

András Guseo

3 plugins · 90 total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect MapSwap for The Events Calendar

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mapswap-for-the-events-calendar/src/js/mapswap-for-the-events-calendar.js/wp-content/plugins/mapswap-for-the-events-calendar/src/css/mapswap-for-the-events-calendar.css
Script Paths
/wp-content/plugins/mapswap-for-the-events-calendar/src/js/mapswap-for-the-events-calendar.js
Version Parameters
mapswap-for-the-events-calendar/src/css/mapswap-for-the-events-calendar.css?ver=mapswap-for-the-events-calendar/src/js/mapswap-for-the-events-calendar.js?ver=

HTML / DOM Fingerprints

Shortcode Output
[leaflet-map[leaflet-marker]
FAQ

Frequently Asked Questions about MapSwap for The Events Calendar