
Nelio Maps Security & Risk Analysis
wordpress.org/plugins/nelio-mapsSimple and beautiful Google Maps block for WordPress.
Is Nelio Maps Safe to Use in 2026?
Generally Safe
Score 100/100Nelio Maps has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the nelio-maps plugin version 2.0.1 exhibits a strong security posture. The absence of identified dangerous functions, raw SQL queries, file operations, and external HTTP requests is highly positive. Furthermore, the code signals indicate a good practice of using prepared statements for SQL queries and generally proper output escaping for most outputs. The plugin also appears to have a minimal attack surface with no publicly exposed entry points like AJAX handlers, REST API routes, or shortcodes that lack authentication or permission checks. The lack of any recorded vulnerabilities, past or present, further reinforces this favorable security assessment.
While the static analysis does not reveal any critical or high-severity issues, the complete absence of nonce checks and capability checks across all analyzed components is a notable concern. This implies that even if entry points existed, they might not be adequately protected against unauthorized access or privilege escalation, especially if the attack surface were to increase in future versions or if specific entry points were missed in this analysis. The taint analysis reporting zero flows, while good, could also be interpreted as an insufficient number of flows being analyzed to definitively rule out all potential taint issues.
In conclusion, nelio-maps v2.0.1 demonstrates a solid foundation with robust practices in areas like SQL handling and output sanitization, and a clean vulnerability history. However, the complete lack of nonce and capability checks represents a potential weakness that could be exploited if vulnerabilities are introduced or if previously undiscovered entry points exist. It's recommended to implement these crucial security checks in any future development to further strengthen the plugin's defense.
Key Concerns
- Missing nonce checks
- Missing capability checks
Nelio Maps Security Vulnerabilities
Nelio Maps Release Timeline
Nelio Maps Code Analysis
Output Escaping
Nelio Maps Attack Surface
WordPress Hooks 7
Maintenance & Trust
Nelio Maps Maintenance & Trust
Maintenance Signals
Community Trust
Nelio Maps Alternatives
Map Block for Google Maps
map-block-gutenberg
Map block for Gutenberg editor powered by Google Maps. Simple. Fast. Just a map block.
WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map by aBlocks
wp-map-block
No API key is required to launch Google Maps & OpenStreetMap.
Geomap – Google Map Block
geomap-block
Simple Google Map Block for WordPress – Add a map to the block editor, no API key required.
Gosign – Google Maps Block
gosign-google-maps-block
Add Google Maps, Custom Style Google Maps, Markers, Info Windows, Marker animations and many more.
GeoVerse Maps
advanced-google-map-block
🚀 Create stunning Google Maps without API key. Perfect for business locations, store finders, and local SEO.
Nelio Maps Developer Profile
12 plugins · 12K total installs
How We Detect Nelio Maps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nelio-maps/assets/dist/blocks/google-map/https://maps.googleapis.com/maps/api/jsnelio-maps/assets/dist/blocks/google-map/index.js?ver=HTML / DOM Fingerprints
NelioMaps