Maps from Yandex for Elementor Security & Risk Analysis

wordpress.org/plugins/mihdan-elementor-yandex-maps

Yandex Maps widget for Elementor

7K active installs v1.7.1 PHP 7.4+ WP 6.6+ Updated Oct 16, 2025
apielementormapsmihdanyandex
99
A · Safe
CVEs total1
Unpatched0
Last CVESep 29, 2025
Safety Verdict

Is Maps from Yandex for Elementor Safe to Use in 2026?

Generally Safe

Score 99/100

Maps from Yandex for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Sep 29, 2025Updated 5mo ago
Risk Assessment

The mihdan-elementor-yandex-maps plugin, version 1.7.1, exhibits a generally strong security posture based on the provided static analysis. The absence of any dangerous functions, raw SQL queries, file operations, or external HTTP requests is a significant positive. Furthermore, all identified output operations are properly escaped, mitigating common cross-site scripting risks. The plugin also demonstrates a clean taint analysis with no unsanitized flows, which is a reassuring sign of secure coding practices in this area. The zero-count for AJAX handlers, REST API routes, shortcodes, and cron events suggests a minimal attack surface, especially with none of these being unprotected.

However, a notable concern arises from the vulnerability history, which indicates one known CVE. While this CVE is not currently unpatched, the presence of a past vulnerability, particularly one related to Cross-site Scripting, suggests that the plugin has had security weaknesses. The fact that the last vulnerability was recorded in 2025-09-29 is a temporal anomaly and should be treated with caution; assuming this date is accurate, it implies a recent historical vulnerability. The absence of capability checks and nonce checks is also a point of attention, although in the context of zero entry points, this might be less immediately critical. The plugin's reliance on Elementor likely means much of its security is inherited from the parent plugin, but direct checks within the plugin itself would further enhance its security.

Key Concerns

  • Past vulnerability recorded
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
1

Maps from Yandex for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-8608medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Mihdan: Elementor Yandex Maps <= 1.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Marker Pins

Sep 29, 2025 Patched in 1.7.0 (15d)
Code Analysis
Analyzed Mar 16, 2026

Maps from Yandex for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
18 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped18 total outputs
Attack Surface

Maps from Yandex for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionelementor/initincludes\class-main.php:111
actionelementor/admin/after_create_settings/elementorincludes\class-main.php:112
actionelementor/editor/before_enqueue_scriptsincludes\class-main.php:113
actionelementor/frontend/after_enqueue_stylesincludes\class-main.php:114
actionelementor/frontend/after_register_scriptsincludes\class-main.php:115
actionelementor/widgets/registerincludes\class-main.php:116
filterwp_resource_hintsincludes\class-main.php:117
filterplugin_action_linksincludes\class-main.php:118
actionadmin_initincludes\class-main.php:121
Maintenance & Trust

Maps from Yandex for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 16, 2025
PHP min version7.4
Downloads51K

Community Trust

Rating98/100
Number of ratings49
Active installs7K
Developer Profile

Maps from Yandex for Elementor Developer Profile

mihdan

11 plugins · 31K total installs

74
trust score
Avg Security Score
93/100
Avg Patch Time
165 days
View full developer profile
Detection Fingerprints

How We Detect Maps from Yandex for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/mihdan-elementor-yandex-maps/admin/css/mihdan-elementor-yandex-maps-admin.css/wp-content/plugins/mihdan-elementor-yandex-maps/admin/js/mihdan-elementor-yandex-maps-admin.js/wp-content/plugins/mihdan-elementor-yandex-maps/frontend/css/mihdan-elementor-yandex-maps.css/wp-content/plugins/mihdan-elementor-yandex-maps/frontend/js/mihdan-elementor-yandex-maps.js
Script Paths
https://api-maps.yandex.ru/2.1/?lang=ru_RU&source=admin&apikey=
Version Parameters
/mihdan-elementor-yandex-maps/admin/css/mihdan-elementor-yandex-maps-admin.css?ver=/mihdan-elementor-yandex-maps/admin/js/mihdan-elementor-yandex-maps-admin.js?ver=/mihdan-elementor-yandex-maps/frontend/css/mihdan-elementor-yandex-maps.css?ver=/mihdan-elementor-yandex-maps/frontend/js/mihdan-elementor-yandex-maps.js?ver=

HTML / DOM Fingerprints

CSS Classes
mihdan-elementor-yandex-maps-admin-wrap
Data Attributes
data-plugin-urldata-api-key
JS Globals
mihdan_elementor_yandex_maps_config
FAQ

Frequently Asked Questions about Maps from Yandex for Elementor