
MW Google Maps Security & Risk Analysis
wordpress.org/plugins/mw-google-mapsMW Google Maps adds google maps in your post easy.
Is MW Google Maps Safe to Use in 2026?
Generally Safe
Score 85/100MW Google Maps has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mw-google-maps" v1.3.1 plugin exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, all SQL queries utilizing prepared statements, and the presence of nonce and capability checks are strong indicators of secure coding practices. Furthermore, the lack of any known historical CVEs suggests a mature and well-maintained codebase.
However, a significant concern arises from the output escaping. With 58% of outputs properly escaped, it implies that nearly half of the plugin's output is not being sanitized. This leaves the plugin vulnerable to Cross-Site Scripting (XSS) attacks, especially considering the presence of two shortcodes which often serve as entry points for user-provided data. While the total number of entry points is low and none are immediately unprotected in the static analysis, the potential for unsanitized output flowing from these shortcodes into the rendered page is a tangible risk. Taint analysis showed no unsanitized paths, which is positive, but this does not negate the risk posed by the high percentage of improperly escaped outputs.
In conclusion, the plugin demonstrates strengths in its handling of database operations and authentication mechanisms, and its vulnerability history is clean. The primary weakness lies in its output sanitization. While the attack surface appears limited and there are no immediate indications of critical code execution vulnerabilities from the static analysis, the potential for XSS through the shortcodes due to insufficient output escaping is the most significant security concern. Addressing the output escaping would significantly enhance the plugin's overall security.
Key Concerns
- Output escaping is not properly handled (42% issues)
MW Google Maps Security Vulnerabilities
MW Google Maps Code Analysis
Output Escaping
Data Flow Analysis
MW Google Maps Attack Surface
Shortcodes 2
WordPress Hooks 10
Maintenance & Trust
MW Google Maps Maintenance & Trust
Maintenance Signals
Community Trust
MW Google Maps Alternatives
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)
leaflet-maps-marker
The most comprehensive & user-friendly mapping solution for WordPress
CodePeople Post Map for Google Maps
codepeople-post-map
CodePeople Post Map lets you geotag posts and seamlessly integrate your blog with Google Maps for a smooth, location-aware experience.
Nomad World Map
nomad-world-map
Create your own custom travel map. Link locations on the map to blog posts and share your travel plans.
WP Map Route Planner
wp-map-route-planner
Help you to locate specific and most direct route, such as WooCommerce order delivery routes or your's custom added route, it integrates a Route …
WP-Routes Plugin
wp-routes
Add Cycle Routes, Mountain Bike Trails, Running Tracks, Walking Routes and much more to your posts and pages.
MW Google Maps Developer Profile
11 plugins · 331K total installs
How We Detect MW Google Maps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mw-google-maps/css/style.css/wp-content/plugins/mw-google-maps/js/jquery.mw-google-maps.jshttp://maps.google.com/maps/api/js?sensor=falsejquery.mw-google-maps?ver=mw-google-maps?ver=HTML / DOM Fingerprints
mw-google-maps-mapid="mw-google-maps-map-multi"id="mw-google-maps-map-data-key="mw-google-maps-map-multi"gmap<div id="mw-google-maps-map-multi" class="mw-google-maps-map"></div><div id="mw-google-maps-map-gmap.mw_google_maps( "addMarker"gmap.mw_google_maps( "useRoute"