
Meks Easy Maps Security & Risk Analysis
wordpress.org/plugins/meks-easy-mapsEasily display map locations for your posts and categories with Google Maps or OSM.
Is Meks Easy Maps Safe to Use in 2026?
Mostly Safe
Score 78/100Meks Easy Maps is generally safe to use. 1 past CVE were resolved.
The 'meks-easy-maps' plugin v2.1.6 exhibits a mixed security posture. On the positive side, the code analysis reveals strong adherence to secure coding practices, with 100% of SQL queries using prepared statements and all identified output being properly escaped. The plugin also incorporates both nonce and capability checks, indicating an effort to protect against common web vulnerabilities. The attack surface appears minimal, with only one shortcode identified and no unprotected entry points. However, the presence of two flows with unsanitized paths, even if not categorized as critical or high severity in the static analysis, warrants attention as it indicates potential pathways for input to be processed without adequate sanitization.
The vulnerability history presents a significant concern. The existence of one known, currently unpatched medium severity CVE related to Cross-site Scripting is a clear indicator of a past security weakness that remains unaddressed. While the static analysis did not flag XSS vulnerabilities, this historical data suggests a potential blind spot or a vulnerability that might be triggered under specific conditions not identified by the static analysis tools. The fact that the last vulnerability was recent (2025-10-02) further emphasizes the need for vigilance.
In conclusion, while 'meks-easy-maps' v2.1.6 demonstrates good fundamental security practices in its code, the presence of unsanitized path flows and, more importantly, an unpatched medium severity XSS vulnerability, significantly lowers its overall security rating. Users should be aware of the historical risk and prioritize updating to a version that addresses the known CVE.
Key Concerns
- Unpatched CVE (medium severity)
- Flows with unsanitized paths
Meks Easy Maps Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Meks Easy Maps <= 2.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting
Meks Easy Maps Release Timeline
Meks Easy Maps Code Analysis
Output Escaping
Data Flow Analysis
Meks Easy Maps Attack Surface
Shortcodes 1
WordPress Hooks 19
Maintenance & Trust
Meks Easy Maps Maintenance & Trust
Maintenance Signals
Community Trust
Meks Easy Maps Alternatives
Easy Google Maps
google-maps-easy
Google Maps with markers, locations and clusterization, KML layers and filters. Custom Google map markers with text, images, videos, links.
Store Locator WordPress
agile-store-locator
Agile Store Locator is a premium store finder plugin designed to offer you immediate access to all the best stores in your local area.
Geo Mashup
geo-mashup
Include Google and OpenStreetMap maps in posts and pages, and map posts, pages, and other objects on global maps. Make WordPress into a GeoCMS.
Kikote – Location Picker at Checkout & Google Address AutoFill Plugin for WooCommerce
map-location-picker-at-checkout-for-woocommerce
Allow customers to select delivery/pickup spots on Google Maps at Checkout. Create shipping workflows for smooth order handling and better pricing.
Store Locator for WordPress📍
storelocator
Create a store locator for your website in minutes. Add all the store locations in google sheets and embed map on your website.
Meks Easy Maps Developer Profile
14 plugins · 117K total installs
How We Detect Meks Easy Maps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/meks-easy-maps/admin/css/admin.css/wp-content/plugins/meks-easy-maps/public/css/leaflet.css/wp-content/plugins/meks-easy-maps/admin/js/esri-leaflet-geocoder.css/wp-content/plugins/meks-easy-maps/public/js/leaflet.js/wp-content/plugins/meks-easy-maps/admin/js/esri-leaflet.js/wp-content/plugins/meks-easy-maps/admin/js/esri-leaflet-geocoder.js/wp-content/plugins/meks-easy-maps/admin/js/esri-leaflet-geocoder-input.js/wp-content/plugins/meks-easy-maps/admin/js/admin-osm.js+1 morehttps://maps.google.com/maps/api/js?key=/wp-content/plugins/meks-easy-maps/admin/js/admin-map.js/wp-content/plugins/meks-easy-maps/public/js/leaflet.js/wp-content/plugins/meks-easy-maps/admin/js/esri-leaflet.js/wp-content/plugins/meks-easy-maps/admin/js/esri-leaflet-geocoder.js/wp-content/plugins/meks-easy-maps/admin/js/esri-leaflet-geocoder-input.js+1 moremeks-easy-maps/admin/css/admin.css?ver=meks-easy-maps/public/css/leaflet.css?ver=meks-easy-maps/admin/js/esri-leaflet-geocoder.css?ver=meks-easy-maps/public/js/leaflet.js?ver=meks-easy-maps/admin/js/esri-leaflet.js?ver=meks-easy-maps/admin/js/esri-leaflet-geocoder.js?ver=meks-easy-maps/admin/js/esri-leaflet-geocoder-input.js?ver=meks-easy-maps/admin/js/admin-osm.js?ver=meks-easy-maps/admin/js/admin-map.js?ver=HTML / DOM Fingerprints
mks_map_meta_boxdata-map-iddata-map-sourceMKS_MAP_VER