Navionics WebAPI v2 Security & Risk Analysis

wordpress.org/plugins/nwa

Navionics WebAPIv2 WordPress plugin allows you to easily add Navionics maps to your Wordpress blog.

50 active installs v0.2.0 PHP + WP 4.7.2+ Updated May 27, 2019
chartmapsnauticalnavionics
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Navionics WebAPI v2 Safe to Use in 2026?

Generally Safe

Score 85/100

Navionics WebAPI v2 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The "nwa" plugin v0.2.0 exhibits a generally strong security posture based on the provided static analysis. The absence of any identified vulnerabilities in its history is a positive indicator. The plugin also demonstrates good practices by avoiding dangerous functions, having no file operations or external HTTP requests, and utilizing prepared statements for all its SQL queries. However, a significant concern arises from the low percentage (33%) of properly escaped outputs. This indicates a potential for Cross-Site Scripting (XSS) vulnerabilities, as untrusted data might be rendered directly in the browser without sufficient sanitization. While the static analysis found no taint flows with unsanitized paths, this is likely due to the limited scope of the analysis or the lack of complex data manipulation. The presence of nonce checks is a positive step, but the lack of capability checks on any entry points is a notable weakness.

Key Concerns

  • Low percentage of properly escaped outputs
  • No capability checks on entry points
Vulnerabilities
None known

Navionics WebAPI v2 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Navionics WebAPI v2 Release Timeline

v0.2.0Current
v0.1.0
Code Analysis
Analyzed Mar 16, 2026

Navionics WebAPI v2 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
6 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

33% escaped18 total outputs
Attack Surface

Navionics WebAPI v2 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 20
actionplugins_loadedincludes\class-nwa.php:154
actioninitincludes\class-nwa.php:171
actionadmin_enqueue_scriptsincludes\class-nwa.php:172
actionadmin_enqueue_scriptsincludes\class-nwa.php:173
actionwp_enqueue_scriptsincludes\class-nwa.php:191
actionwp_enqueue_scriptsincludes\class-nwa.php:192
actionwp_enqueue_scriptsincludes\class-nwa.php:194
actionwp_enqueue_scriptsincludes\class-nwa.php:195
actionadd_meta_boxesincludes\class-webapi-meta-box.php:49
actionsave_postincludes\class-webapi-meta-box.php:50
actionplugins_loadedtrunk\includes\class-nwa.php:154
actioninittrunk\includes\class-nwa.php:171
actionadmin_enqueue_scriptstrunk\includes\class-nwa.php:172
actionadmin_enqueue_scriptstrunk\includes\class-nwa.php:173
actionwp_enqueue_scriptstrunk\includes\class-nwa.php:191
actionwp_enqueue_scriptstrunk\includes\class-nwa.php:192
actionwp_enqueue_scriptstrunk\includes\class-nwa.php:194
actionwp_enqueue_scriptstrunk\includes\class-nwa.php:195
actionadd_meta_boxestrunk\includes\class-webapi-meta-box.php:49
actionsave_posttrunk\includes\class-webapi-meta-box.php:50
Maintenance & Trust

Navionics WebAPI v2 Maintenance & Trust

Maintenance Signals

WordPress version tested5.2.24
Last updatedMay 27, 2019
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs50
Developer Profile

Navionics WebAPI v2 Developer Profile

navionicsdevelopers

1 plugin · 50 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Navionics WebAPI v2

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/nwa/css/nwa-admin.css/wp-content/plugins/nwa/js/nwa-admin.js
Script Paths
/wp-content/plugins/nwa/js/nwa-admin.js
Version Parameters
nwa-admin.css?ver=nwa-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
test_map_div
Data Attributes
data-navkeydata-centerdata-tagiddata-custom-js-codedata-custom-css-code
JS Globals
JNC.Views.BoatingNavionicsMap
Shortcode Output
[nwa
FAQ

Frequently Asked Questions about Navionics WebAPI v2