Meks Easy Maps Security & Risk Analysis

wordpress.org/plugins/meks-easy-maps

Easily display map locations for your posts and categories with Google Maps or OSM.

900 active installs v2.1.6 PHP + WP 3.7+ Updated Mar 4, 2026
destinationgoogle-maplocationmappin
78
B · Generally Safe
CVEs total1
Unpatched1
Last CVEOct 2, 2025
Safety Verdict

Is Meks Easy Maps Safe to Use in 2026?

Mostly Safe

Score 78/100

Meks Easy Maps is generally safe to use. 1 past CVE were resolved.

1 known CVE 1 unpatched Last CVE: Oct 2, 2025Updated 2mo ago
Risk Assessment

The 'meks-easy-maps' plugin v2.1.6 exhibits a mixed security posture. On the positive side, the code analysis reveals strong adherence to secure coding practices, with 100% of SQL queries using prepared statements and all identified output being properly escaped. The plugin also incorporates both nonce and capability checks, indicating an effort to protect against common web vulnerabilities. The attack surface appears minimal, with only one shortcode identified and no unprotected entry points. However, the presence of two flows with unsanitized paths, even if not categorized as critical or high severity in the static analysis, warrants attention as it indicates potential pathways for input to be processed without adequate sanitization.

The vulnerability history presents a significant concern. The existence of one known, currently unpatched medium severity CVE related to Cross-site Scripting is a clear indicator of a past security weakness that remains unaddressed. While the static analysis did not flag XSS vulnerabilities, this historical data suggests a potential blind spot or a vulnerability that might be triggered under specific conditions not identified by the static analysis tools. The fact that the last vulnerability was recent (2025-10-02) further emphasizes the need for vigilance.

In conclusion, while 'meks-easy-maps' v2.1.6 demonstrates good fundamental security practices in its code, the presence of unsanitized path flows and, more importantly, an unpatched medium severity XSS vulnerability, significantly lowers its overall security rating. Users should be aware of the historical risk and prioritize updating to a version that addresses the known CVE.

Key Concerns

  • Unpatched CVE (medium severity)
  • Flows with unsanitized paths
Vulnerabilities
1 published

Meks Easy Maps Security Vulnerabilities

CVEs by Year

1 CVE in 2025 · unpatched
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-9206medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Meks Easy Maps <= 2.1.4 - Authenticated (Contributor+) Stored Cross-Site Scripting

Oct 2, 2025Unpatched
Version History

Meks Easy Maps Release Timeline

v2.1.51 CVE
v2.1.41 CVE
v2.1.21 CVE
Code Analysis
Analyzed Mar 16, 2026

Meks Easy Maps Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
138 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped138 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

4 flows2 with unsanitized paths
print_settings_page (admin\settings-page.php:78)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Meks Easy Maps Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[mks_map] public\map.php:193
WordPress Hooks 19
actionedited_categoryadmin\category-metabox-map.php:8
actioncreate_categoryadmin\category-metabox-map.php:9
actioncategory_add_form_fieldsadmin\category-metabox-map.php:12
actioncategory_edit_form_fieldsadmin\category-metabox-map.php:13
actionadmin_enqueue_scriptsadmin\enqueue.php:8
actionadmin_enqueue_scriptsadmin\enqueue.php:63
actionload-post.phpadmin\post-metabox-map.php:7
actionload-post-new.phpadmin\post-metabox-map.php:8
actionadd_meta_boxesadmin\post-metabox-map.php:13
actionsave_postadmin\post-metabox-map.php:14
actionadmin_menuadmin\settings-page.php:46
actionadmin_enqueue_scriptsadmin\settings-page.php:47
actionadmin_initadmin\settings-page.php:52
actionadmin_initadmin\settings-page.php:54
actionadmin_initadmin\settings-page.php:56
actionplugins_loadedmeks-easy-maps.php:28
actionwp_enqueue_scriptspublic\map.php:7
filterthe_contentpublic\map.php:92
filtercategory_descriptionpublic\map.php:147
Maintenance & Trust

Meks Easy Maps Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 4, 2026
PHP min version
Downloads15K

Community Trust

Rating0/100
Number of ratings0
Active installs900
Developer Profile

Meks Easy Maps Developer Profile

Meks

14 plugins · 117K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
236 days
View full developer profile
Detection Fingerprints

How We Detect Meks Easy Maps

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/meks-easy-maps/admin/css/admin.css/wp-content/plugins/meks-easy-maps/public/css/leaflet.css/wp-content/plugins/meks-easy-maps/admin/js/esri-leaflet-geocoder.css/wp-content/plugins/meks-easy-maps/public/js/leaflet.js/wp-content/plugins/meks-easy-maps/admin/js/esri-leaflet.js/wp-content/plugins/meks-easy-maps/admin/js/esri-leaflet-geocoder.js/wp-content/plugins/meks-easy-maps/admin/js/esri-leaflet-geocoder-input.js/wp-content/plugins/meks-easy-maps/admin/js/admin-osm.js+1 more
Script Paths
https://maps.google.com/maps/api/js?key=/wp-content/plugins/meks-easy-maps/admin/js/admin-map.js/wp-content/plugins/meks-easy-maps/public/js/leaflet.js/wp-content/plugins/meks-easy-maps/admin/js/esri-leaflet.js/wp-content/plugins/meks-easy-maps/admin/js/esri-leaflet-geocoder.js/wp-content/plugins/meks-easy-maps/admin/js/esri-leaflet-geocoder-input.js+1 more
Version Parameters
meks-easy-maps/admin/css/admin.css?ver=meks-easy-maps/public/css/leaflet.css?ver=meks-easy-maps/admin/js/esri-leaflet-geocoder.css?ver=meks-easy-maps/public/js/leaflet.js?ver=meks-easy-maps/admin/js/esri-leaflet.js?ver=meks-easy-maps/admin/js/esri-leaflet-geocoder.js?ver=meks-easy-maps/admin/js/esri-leaflet-geocoder-input.js?ver=meks-easy-maps/admin/js/admin-osm.js?ver=meks-easy-maps/admin/js/admin-map.js?ver=

HTML / DOM Fingerprints

CSS Classes
mks_map_meta_box
Data Attributes
data-map-iddata-map-source
JS Globals
MKS_MAP_VER
FAQ

Frequently Asked Questions about Meks Easy Maps