
Nearby Places Search Security & Risk Analysis
wordpress.org/plugins/nearby-places-searchNearby Places Search: This Plugin integrates with the Google Places and GMap.
Is Nearby Places Search Safe to Use in 2026?
Generally Safe
Score 85/100Nearby Places Search has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nearby-places-search" v1 plugin exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, and file operations, coupled with 100% of SQL queries using prepared statements, indicates a commitment to secure coding practices. The high percentage of properly escaped output (93%) is also commendable, mitigating common cross-site scripting (XSS) risks. The plugin also correctly leverages capability checks for its single entry point, the shortcode.
However, a notable concern is the complete lack of nonce checks. While the static analysis doesn't reveal any direct vulnerabilities from this, it represents a significant gap in protecting against Cross-Site Request Forgery (CSRF) attacks. Any function that modifies data or performs sensitive actions should ideally be protected by nonces. The absence of taint analysis data also means that potential vulnerabilities in complex data flows might have been missed. The vulnerability history being clear of any CVEs is a strong positive, suggesting the plugin has historically been well-maintained and secure, but this cannot entirely compensate for the identified lack of nonce protection.
In conclusion, "nearby-places-search" v1 shows strengths in its handling of SQL and output sanitization, and its minimal attack surface is well-protected by capability checks. The primary area for improvement and a clear security risk is the absence of nonce checks, which should be addressed to prevent potential CSRF vulnerabilities. Without this, the plugin's overall security is good but not excellent.
Key Concerns
- Missing nonce checks
Nearby Places Search Security Vulnerabilities
Nearby Places Search Code Analysis
Output Escaping
Nearby Places Search Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Nearby Places Search Maintenance & Trust
Maintenance Signals
Community Trust
Nearby Places Search Alternatives
Wp Maps
wp-maps
Integrate Google Maps easily in your site, no coding required. Use custom icons and colors for each location or route. Show unlimited maps.
Store Manager
store-manager
Store manager with control over opening hours, location, images and much more.
Woo order google map location finder
woo-order-google-map-location-finder
Woo order google map location finder helps to find delivery location of ordered items.It is working with WooCommerce only.
WP Geoloc
wp-geoloc
Search for posts around a location with a specific distance.
Loginizer
loginizer
Loginizer is a WordPress security plugin which helps you fight against bruteforce attacks.
Nearby Places Search Developer Profile
1 plugin · 10 total installs
How We Detect Nearby Places Search
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nearby-places-search/css/nearby_places_search.css/wp-content/plugins/nearby-places-search/js/nearby-place.js//maps.googleapis.com/maps/api/jsv=3HTML / DOM Fingerprints
object_name[nearby_places_search_code]