
MIPL Stockist/Store Locator Security & Risk Analysis
wordpress.org/plugins/mipl-stockist-store-locatorCreate a quick Stockist/Store Locator with Google Map, Autocomplete search location & Distance & Category filter.
Is MIPL Stockist/Store Locator Safe to Use in 2026?
Generally Safe
Score 100/100MIPL Stockist/Store Locator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "mipl-stockist-store-locator" v1.3.3 exhibits a mixed security posture with some concerning aspects alongside generally good practices. While the plugin boasts a clean vulnerability history with no recorded CVEs, indicating a potentially stable codebase, the static analysis reveals significant risks. The presence of the `unserialize` function, a known dangerous function, is a notable concern as it can lead to arbitrary code execution if used with untrusted input. Furthermore, the analysis highlights two REST API routes that lack permission callbacks, creating an unprotected attack surface where unauthenticated users could potentially interact with these endpoints. The taint analysis indicates flows with unsanitized paths, though thankfully no critical or high-severity issues were flagged here, suggesting the risks might be contained or mitigated elsewhere. However, the limited number of flows analyzed (9) means this assessment might not be exhaustive.
Overall, the plugin demonstrates good practices in SQL query handling (100% prepared statements) and has a high percentage of properly escaped output. The ample nonce checks are also a positive sign for security. Despite the lack of historical vulnerabilities, the identified weaknesses, particularly the unprotected REST API endpoints and the use of `unserialize`, warrant careful consideration and mitigation. The absence of capability checks on the identified REST API routes is a critical oversight that significantly increases the risk profile.
Key Concerns
- REST API routes without permission callbacks
- Dangerous function detected (unserialize)
- Flows with unsanitized paths found
- No capability checks on entry points
MIPL Stockist/Store Locator Security Vulnerabilities
MIPL Stockist/Store Locator Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
MIPL Stockist/Store Locator Attack Surface
REST API Routes 2
Shortcodes 1
WordPress Hooks 36
Maintenance & Trust
MIPL Stockist/Store Locator Maintenance & Trust
Maintenance Signals
Community Trust
MIPL Stockist/Store Locator Alternatives
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
Easy Map – Store Locator, Google Maps, OpenStreetMap, Leaflet Map
easy-map
Create interactive maps with store locator, markers, drawings & multiple locations. Supports OpenStreetMap and Google Maps. No API key needed.
Progus Store Locator Map (No API Key Required)
progus-store-locator
Powerful Store, Dealer & Stockist Locator with all features for just $3.99/month. Trusted by 4,000+ businesses worldwide.
Store Locator for WordPress Posts
wp-post-store-locator
This is a wordpress store locator plugin for posts. We can setup stores for individual posts/products.
WP Store Locator
wp-store-locator
An easy to use location management system that enables users to search for nearby physical stores.
MIPL Stockist/Store Locator Developer Profile
6 plugins · 280 total installs
How We Detect MIPL Stockist/Store Locator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mipl-stockist-store-locator/assets/css/mipl-sl-admin-style.css/wp-content/plugins/mipl-stockist-store-locator/assets/css/mipl-sl-frontend-style.css/wp-content/plugins/mipl-stockist-store-locator/assets/js/mipl-sl-admin-script.js/wp-content/plugins/mipl-stockist-store-locator/assets/js/mipl-sl-frontend-script.js/wp-content/plugins/mipl-stockist-store-locator/assets/js/mipl-sl-map-script.js/wp-content/plugins/mipl-stockist-store-locator/assets/js/mipl-sl-admin-script.js/wp-content/plugins/mipl-stockist-store-locator/assets/js/mipl-sl-frontend-script.js/wp-content/plugins/mipl-stockist-store-locator/assets/js/mipl-sl-map-script.js/wp-content/plugins/mipl-stockist-store-locator/include/blocks/blocks.js/wp-content/plugins/mipl-stockist-store-locator/include/blocks/editor.jsmipl-stockist-store-locator/assets/css/mipl-sl-admin-style.css?ver=mipl-stockist-store-locator/assets/css/mipl-sl-frontend-style.css?ver=mipl-stockist-store-locator/assets/js/mipl-sl-admin-script.js?ver=mipl-stockist-store-locator/assets/js/mipl-sl-frontend-script.js?ver=mipl-stockist-store-locator/assets/js/mipl-sl-map-script.js?ver=mipl-stockist-store-locator/include/blocks/blocks.js?ver=mipl-stockist-store-locator/include/blocks/editor.js?ver=HTML / DOM Fingerprints
mipl-sl-map-wrappermipl-sl-store-listingmipl-sl-filter-form<!-- MIPL Stockist/Store Locator Start --><!-- MIPL Stockist/Store Locator End --><!-- MIPL SL Shortcode Start --><!-- MIPL SL Shortcode End -->data-mipl-sl-settingsmipl_sl_frontend_paramsmipl_sl_admin_params/wp-json/mipl-stockist-store-locator/v1/get-stores/wp-json/mipl-stockist-store-locator/v1/get-store-details[mipl_stockist_store_locator]