
Maps from Yandex for Elementor Security & Risk Analysis
wordpress.org/plugins/mihdan-elementor-yandex-mapsYandex Maps widget for Elementor
Is Maps from Yandex for Elementor Safe to Use in 2026?
Generally Safe
Score 99/100Maps from Yandex for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.
The mihdan-elementor-yandex-maps plugin, version 1.7.1, exhibits a generally strong security posture based on the provided static analysis. The absence of any dangerous functions, raw SQL queries, file operations, or external HTTP requests is a significant positive. Furthermore, all identified output operations are properly escaped, mitigating common cross-site scripting risks. The plugin also demonstrates a clean taint analysis with no unsanitized flows, which is a reassuring sign of secure coding practices in this area. The zero-count for AJAX handlers, REST API routes, shortcodes, and cron events suggests a minimal attack surface, especially with none of these being unprotected.
However, a notable concern arises from the vulnerability history, which indicates one known CVE. While this CVE is not currently unpatched, the presence of a past vulnerability, particularly one related to Cross-site Scripting, suggests that the plugin has had security weaknesses. The fact that the last vulnerability was recorded in 2025-09-29 is a temporal anomaly and should be treated with caution; assuming this date is accurate, it implies a recent historical vulnerability. The absence of capability checks and nonce checks is also a point of attention, although in the context of zero entry points, this might be less immediately critical. The plugin's reliance on Elementor likely means much of its security is inherited from the parent plugin, but direct checks within the plugin itself would further enhance its security.
Key Concerns
- Past vulnerability recorded
- Missing nonce checks
- Missing capability checks
Maps from Yandex for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Mihdan: Elementor Yandex Maps <= 1.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting via Marker Pins
Maps from Yandex for Elementor Code Analysis
Output Escaping
Maps from Yandex for Elementor Attack Surface
WordPress Hooks 9
Maintenance & Trust
Maps from Yandex for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
Maps from Yandex for Elementor Alternatives
API KEY for Google Maps
api-key-for-google-maps
Retroactively add Google Maps API KEY to any theme or plugin.
YaMaps for WordPress Plugin
yamaps
The plugin allows you to add Yandex Maps (Яндекс Карты) to pages of your site using a WordPress visual editor.
WP MapIt
wp-mapit
Easy to use, WordPress Map plugin based on Open Street Map and Leaflet with custom markers images, descriptions and links.
Tuskcode Map Pro for Bing Maps
api-bing-map-2018
Designed to create accesible maps from bing, with multiple options of pins, width, height, custom pins, and address.
Maps for WP
maps-for-wp
A handy plugin for inserting Yandex and Google maps using shortcode.
Maps from Yandex for Elementor Developer Profile
11 plugins · 31K total installs
How We Detect Maps from Yandex for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mihdan-elementor-yandex-maps/admin/css/mihdan-elementor-yandex-maps-admin.css/wp-content/plugins/mihdan-elementor-yandex-maps/admin/js/mihdan-elementor-yandex-maps-admin.js/wp-content/plugins/mihdan-elementor-yandex-maps/frontend/css/mihdan-elementor-yandex-maps.css/wp-content/plugins/mihdan-elementor-yandex-maps/frontend/js/mihdan-elementor-yandex-maps.jshttps://api-maps.yandex.ru/2.1/?lang=ru_RU&source=admin&apikey=/mihdan-elementor-yandex-maps/admin/css/mihdan-elementor-yandex-maps-admin.css?ver=/mihdan-elementor-yandex-maps/admin/js/mihdan-elementor-yandex-maps-admin.js?ver=/mihdan-elementor-yandex-maps/frontend/css/mihdan-elementor-yandex-maps.css?ver=/mihdan-elementor-yandex-maps/frontend/js/mihdan-elementor-yandex-maps.js?ver=HTML / DOM Fingerprints
mihdan-elementor-yandex-maps-admin-wrapdata-plugin-urldata-api-keymihdan_elementor_yandex_maps_config