OSM Map Widget for Elementor Security & Risk Analysis

wordpress.org/plugins/osm-map-elementor

A free Elementor Map Widget that utilizes Open Street Map. Comes with features like adding multiple markers, and choosing from a library of custom til …

9K active installs v1.3.1 PHP 7.3+ WP 6.0+ Updated Sep 5, 2025
addonselementorelementor-widgetmap-widgetopen-street-map
98
A · Safe
CVEs total2
Unpatched0
Last CVEAug 28, 2025
Download
Safety Verdict

Is OSM Map Widget for Elementor Safe to Use in 2026?

Generally Safe

Score 98/100

OSM Map Widget for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Aug 28, 2025Updated 7mo ago
Risk Assessment

The static analysis of osm-map-elementor v1.3.1 shows several positive security indicators. The plugin has a clean attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication. Furthermore, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and shows a high percentage of properly escaped output, minimizing the risk of cross-site scripting. Nonce and capability checks are also present, further strengthening its security posture. However, the vulnerability history presents a significant concern. The plugin has had two known medium-severity vulnerabilities, both related to Cross-site Scripting. While currently unpatched CVEs are reported as zero, the existence of past XSS vulnerabilities, especially if they were recently discovered (indicated by the 'last vulnerability' date), suggests potential recurring issues in input sanitization or output escaping that might not have been fully addressed or could resurface. The lack of critical or high-severity taint flows is a positive sign from the static analysis, but it does not entirely negate the historical precedent of XSS flaws. The plugin exhibits strengths in its current code's implementation of common security practices, but its past vulnerability record warrants caution and continued monitoring.

Key Concerns

  • Medium severity XSS vulnerabilities in history
  • Recent past vulnerability (2025-08-28)
  • Output escaping not 100% proper (86%)
Vulnerabilities
2

OSM Map Widget for Elementor Security Vulnerabilities

CVEs by Year

1 CVE in 2024
2024
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-8619medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

OSM Map Widget for Elementor <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button URL

Aug 28, 2025 Patched in 1.3.1 (14d)
CVE-2024-4663medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

OSM Map Widget for Elementor <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter

Jun 18, 2024 Patched in 1.3.0 (15d)
Code Analysis
Analyzed Mar 16, 2026

OSM Map Widget for Elementor Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
36 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

86% escaped42 total outputs
Attack Surface

OSM Map Widget for Elementor Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionelementor/widgets/registerosm-map-elementor.php:20
actionadmin_menuosm-map-elementor.php:33
actionadmin_initosm-map-elementor.php:181
actionadmin_noticesosm-map-elementor.php:183
actioninitosm-map-elementor.php:199
filterwp_enqueue_scriptsosm-map-elementor.php:200
actionwp_print_footer_scriptsosm-map.php:2022
Maintenance & Trust

OSM Map Widget for Elementor Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedSep 5, 2025
PHP min version7.3
Downloads67K

Community Trust

Rating90/100
Number of ratings8
Active installs9K
Developer Profile

OSM Map Widget for Elementor Developer Profile

garbowza

1 plugin · 9K total installs

93
trust score
Avg Security Score
98/100
Avg Patch Time
15 days
View full developer profile
Detection Fingerprints

How We Detect OSM Map Widget for Elementor

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/osm-map-elementor/assets/css/admin.css
Version Parameters
osm-map-elementor/assets/css/admin.css?ver=

HTML / DOM Fingerprints

CSS Classes
osm-map-settingsosm-map-elementor
HTML Comments
<!-- Inline styles for the osm-map widget --><!-- Add inline styles to the osm-map widget --><!-- Elementor Frontend Addon --><!-- Frontend Styles -->+6 more
Data Attributes
name="osm_widget[gmaps_key]"name="osm_widget[mapbox_token]"name="osm_widget[geoapify_key]"name="osm_widget[enable_fontawesome]"name="osm_widget[osm_custom]"name="osm_widget[osm_custom_attribution]"+1 more
JS Globals
OSM_MAP_SLUGOSM_MAP_VERSIONosm_widget_options
FAQ

Frequently Asked Questions about OSM Map Widget for Elementor