
Open User Map Security & Risk Analysis
wordpress.org/plugins/open-user-mapEngage your visitors with an interactive map – let them add markers instantly or create a custom map showcasing your favorite spots.
Is Open User Map Safe to Use in 2026?
Generally Safe
Score 96/100Open User Map has a strong security track record. Known vulnerabilities have been patched promptly.
The open-user-map plugin v1.4.34 presents a mixed security posture. While it demonstrates some good practices, such as a high percentage of SQL queries using prepared statements and a decent number of capability checks, significant concerns arise from the static analysis. The presence of 14 AJAX handlers, with 3 lacking authentication checks, creates a substantial attack surface that could be exploited without proper user authorization. Furthermore, the taint analysis reveals 4 flows with unsanitized paths, although thankfully none are flagged as critical or high severity, this still represents a potential risk of path traversal vulnerabilities if these flows are not properly handled in conjunction with other security controls. The plugin's vulnerability history shows 3 medium-severity CVEs, specifically related to Path Traversal and Cross-site Scripting. While there are currently no unpatched CVEs, the recurring nature of these vulnerability types suggests a potential weakness in input sanitization and output escaping that needs ongoing vigilance and remediation. The last reported vulnerability in 2026 is also an anomaly that requires further investigation, but assuming it represents a historical event, the recurring nature of past issues is the primary concern.
Key Concerns
- Unprotected AJAX handlers
- Flows with unsanitized paths
- Medium severity CVEs historically
- Low percentage of properly escaped output
- Bundled outdated library (Freemius v1.0)
Open User Map Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Open User Map <= 1.4.16 - Authenticated (Subscriber+) Arbitrary File Download
Open User Map <= 1.4.14 - Authenticated (Contributor+) Stored Cross-Site Scripting
Open User Map | Everybody can add locations <= 1.3.26 - Authenticated (Administrator+) Stored Cross-Site Scripting
Open User Map Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Open User Map Attack Surface
AJAX Handlers 14
Shortcodes 2
WordPress Hooks 65
Maintenance & Trust
Open User Map Maintenance & Trust
Maintenance Signals
Community Trust
Open User Map Alternatives
Mapster WP Maps
mapster-wp-maps
Mapster WP Maps is the smoothest, easiest way to make maps for your site. No API keys required.
WP Mapbox GL JS Maps
wp-mapbox-gl-js
NOTE: This plugin has been deprecated and is no longer supported. Please see our latest plugin, Mapster WP Maps, for a more up-to-date and maintained …
Treweler Map Builder
treweler-map-builder
The Treweler plugin is a multifunction map builder. Its purpose is to help you create an interactive map for your personal or business project.
Your Current Location On Map
your-current-location-on-map
Displays your current location in map with accuracy. Your Current Location On Map plugin is very easy to use,mobile friendly,responsive.
OSMaps
osmaps
Plugin to view free road maps.
Open User Map Developer Profile
3 plugins · 10K total installs
How We Detect Open User Map
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/open-user-map/assets/js/backend/admin.js/wp-content/plugins/open-user-map/assets/js/frontend.js/wp-content/plugins/open-user-map/assets/css/admin.css/wp-content/plugins/open-user-map/assets/css/frontend.css/wp-content/plugins/open-user-map/assets/css/leaflet.css/wp-content/plugins/open-user-map/assets/css/markercluster.css/wp-content/plugins/open-user-map/assets/js/leaflet.js/wp-content/plugins/open-user-map/assets/js/markercluster.js/wp-content/plugins/open-user-map/assets/js/backend/admin.js/wp-content/plugins/open-user-map/assets/js/frontend.js/wp-content/plugins/open-user-map/assets/js/leaflet.js/wp-content/plugins/open-user-map/assets/js/markercluster.jsopen-user-map/assets/js/backend/admin.js?ver=open-user-map/assets/js/frontend.js?ver=open-user-map/assets/css/admin.css?ver=open-user-map/assets/css/frontend.css?ver=open-user-map/assets/css/leaflet.css?ver=open-user-map/assets/css/markercluster.css?ver=open-user-map/assets/js/leaflet.js?ver=open-user-map/assets/js/markercluster.js?ver=HTML / DOM Fingerprints
oum-wizardoum-wizard .herooum-wizard .hero .logooum-wizard .hero .overlineoum-wizard .hero h1oum-wizard .hero .stepsoum-wizard .hero .steps lioum-wizard .step-contentFREEMIUS INTEGRATION CODE<!-- Init Freemius --><!-- Signal that SDK was initiated --><!-- Better Opt-In Screen -->+11 moredata-freemius-slug="open-user-map"data-freemius-type="plugin"data-freemius-id="9083"oum_fs/wp-json/open-user-map/v1/location