Nelio Maps Security & Risk Analysis

wordpress.org/plugins/nelio-maps

Simple and beautiful Google Maps block for WordPress.

20 active installs v2.0.1 PHP 7.4+ WP 6.6+ Updated Dec 2, 2025
blockgoogle-mapsgutenbergmap
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Nelio Maps Safe to Use in 2026?

Generally Safe

Score 100/100

Nelio Maps has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the nelio-maps plugin version 2.0.1 exhibits a strong security posture. The absence of identified dangerous functions, raw SQL queries, file operations, and external HTTP requests is highly positive. Furthermore, the code signals indicate a good practice of using prepared statements for SQL queries and generally proper output escaping for most outputs. The plugin also appears to have a minimal attack surface with no publicly exposed entry points like AJAX handlers, REST API routes, or shortcodes that lack authentication or permission checks. The lack of any recorded vulnerabilities, past or present, further reinforces this favorable security assessment.

While the static analysis does not reveal any critical or high-severity issues, the complete absence of nonce checks and capability checks across all analyzed components is a notable concern. This implies that even if entry points existed, they might not be adequately protected against unauthorized access or privilege escalation, especially if the attack surface were to increase in future versions or if specific entry points were missed in this analysis. The taint analysis reporting zero flows, while good, could also be interpreted as an insufficient number of flows being analyzed to definitively rule out all potential taint issues.

In conclusion, nelio-maps v2.0.1 demonstrates a solid foundation with robust practices in areas like SQL handling and output sanitization, and a clean vulnerability history. However, the complete lack of nonce and capability checks represents a potential weakness that could be exploited if vulnerabilities are introduced or if previously undiscovered entry points exist. It's recommended to implement these crucial security checks in any future development to further strengthen the plugin's defense.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Nelio Maps Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Nelio Maps Release Timeline

v2.0.1Current
v2.0.0
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Nelio Maps Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
1
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

80% escaped5 total outputs
Attack Surface

Nelio Maps Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actioninitclass-nelio-maps.php:74
actioninitclass-nelio-maps.php:75
filterblock_categories_allclass-nelio-maps.php:76
actionwp_enqueue_scriptsclass-nelio-maps.php:77
actionadmin_enqueue_scriptsclass-nelio-maps.php:78
actionadmin_menuoptions.php:19
actionadmin_initoptions.php:54
Maintenance & Trust

Nelio Maps Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 2, 2025
PHP min version7.4
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Nelio Maps Developer Profile

Nelio Software

12 plugins · 12K total installs

75
trust score
Avg Security Score
94/100
Avg Patch Time
760 days
View full developer profile
Detection Fingerprints

How We Detect Nelio Maps

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nelio-maps/assets/dist/blocks/google-map/
Script Paths
https://maps.googleapis.com/maps/api/js
Version Parameters
nelio-maps/assets/dist/blocks/google-map/index.js?ver=

HTML / DOM Fingerprints

JS Globals
NelioMaps
FAQ

Frequently Asked Questions about Nelio Maps