
Nomad World Map Security & Risk Analysis
wordpress.org/plugins/nomad-world-mapCreate your own custom travel map. Link locations on the map to blog posts and share your travel plans.
Is Nomad World Map Safe to Use in 2026?
Generally Safe
Score 85/100Nomad World Map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "nomad-world-map" plugin v1.3.1 exhibits a generally good security posture, with a robust implementation of WordPress security best practices such as nonce and capability checks across all identified entry points. The absence of known CVEs and historical vulnerabilities further bolsters confidence in its security track record. However, the static analysis reveals some areas that warrant attention.
The presence of the `create_function` function is a notable concern, as it is considered deprecated and can lead to security vulnerabilities if not handled with extreme care, potentially allowing for arbitrary code execution. Additionally, the taint analysis highlights three high-severity flows with unsanitized paths. While the exact nature of these flows is not detailed, this indicates potential pathways for attackers to inject malicious data that is not properly validated or sanitized before being used, which could lead to various exploits depending on the context.
Despite these identified risks, the plugin demonstrates strengths in its limited attack surface, especially with no unprotected AJAX handlers or REST API routes. The majority of SQL queries utilize prepared statements and a significant portion of output is properly escaped. The vulnerability history being clear is a positive indicator of past development practices. Overall, while the plugin benefits from a clean security history and good implementation of core WordPress security features, the specific findings from static analysis regarding `create_function` and high-severity unsanitized paths require investigation and remediation to ensure its continued security.
Key Concerns
- High severity unsanitized paths found in taint analysis
- Use of dangerous function 'create_function'
Nomad World Map Security Vulnerabilities
Nomad World Map Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Nomad World Map Attack Surface
AJAX Handlers 7
Shortcodes 2
WordPress Hooks 10
Maintenance & Trust
Nomad World Map Maintenance & Trust
Maintenance Signals
Community Trust
Nomad World Map Alternatives
Travelmap
travelmap
Generates a map of your travels in any post or page based on a list of places.
CodePeople Post Map for Google Maps
codepeople-post-map
CodePeople Post Map lets you geotag posts and seamlessly integrate your blog with Google Maps for a smooth, location-aware experience.
Car Route Planner Plugin
car-route-planner
Route planner for car travelers. Calculator of various values for route, such as length, driving time, fuel amount and cost, customized cost.
Polarsteps Integration
integrate-polarsteps
Wordpress Plugin to integrate Travel Data from Polarsteps within a widget.
MK Google Directions
google-distance-calculator
Enable use of Google Directions in your WordPress blog.
Nomad World Map Developer Profile
1 plugin · 700 total installs
How We Detect Nomad World Map
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/nomad-world-map/css/nwm-frontend.css/wp-content/plugins/nomad-world-map/css/nwm-admin.css/wp-content/plugins/nomad-world-map/js/nwm-frontend.js/wp-content/plugins/nomad-world-map/js/nwm-admin.js/wp-content/plugins/nomad-world-map/js/nwm-frontend.js/wp-content/plugins/nomad-world-map/js/nwm-admin.jsnomad-world-map/css/nwm-frontend.css?ver=nomad-world-map/css/nwm-admin.css?ver=nomad-world-map/js/nwm-frontend.js?ver=nomad-world-map/js/nwm-admin.js?ver=HTML / DOM Fingerprints
nwm-map-canvasnwm-location-marker<!-- Nomad World Map --><!-- Nomad World Map Admin Settings -->data-map-iddata-location-idnwm_frontend_optionsnwm_admin_options/wp-json/nwm/v1/locations/wp-json/nwm/v1/map[nwm_map][nwm_route]