
OSM Map Widget for Elementor Security & Risk Analysis
wordpress.org/plugins/osm-map-elementorA free Elementor Map Widget that utilizes Open Street Map. Comes with features like adding multiple markers, and choosing from a library of custom til …
Is OSM Map Widget for Elementor Safe to Use in 2026?
Generally Safe
Score 98/100OSM Map Widget for Elementor has a strong security track record. Known vulnerabilities have been patched promptly.
The static analysis of osm-map-elementor v1.3.1 shows several positive security indicators. The plugin has a clean attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that lack authentication. Furthermore, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and shows a high percentage of properly escaped output, minimizing the risk of cross-site scripting. Nonce and capability checks are also present, further strengthening its security posture. However, the vulnerability history presents a significant concern. The plugin has had two known medium-severity vulnerabilities, both related to Cross-site Scripting. While currently unpatched CVEs are reported as zero, the existence of past XSS vulnerabilities, especially if they were recently discovered (indicated by the 'last vulnerability' date), suggests potential recurring issues in input sanitization or output escaping that might not have been fully addressed or could resurface. The lack of critical or high-severity taint flows is a positive sign from the static analysis, but it does not entirely negate the historical precedent of XSS flaws. The plugin exhibits strengths in its current code's implementation of common security practices, but its past vulnerability record warrants caution and continued monitoring.
Key Concerns
- Medium severity XSS vulnerabilities in history
- Recent past vulnerability (2025-08-28)
- Output escaping not 100% proper (86%)
OSM Map Widget for Elementor Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
OSM Map Widget for Elementor <= 1.3.0 - Authenticated (Contributor+) Stored Cross-Site Scripting via Button URL
OSM Map Widget for Elementor <= 1.2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via id Parameter
OSM Map Widget for Elementor Code Analysis
Output Escaping
OSM Map Widget for Elementor Attack Surface
WordPress Hooks 7
Maintenance & Trust
OSM Map Widget for Elementor Maintenance & Trust
Maintenance Signals
Community Trust
OSM Map Widget for Elementor Alternatives
ElementsKit Elementor Addons – Advanced Widgets & Templates Addons for Elementor
elementskit-lite
Join millions who empower their websites with ElementsKit Elementor Addons. Get templates, & 100+ widgets like header-footer, mega menu, custom widget
Essential Addons for Elementor – Popular Elementor Templates & Widgets
essential-addons-for-elementor-lite
Elementor addon offering 110+ widgets and templates — Elementor Gallery, Slider, Form, Post Grid, Menu, Accordion, WooCommerce & more.
Ultimate Addons for Elementor
header-footer-elementor
Powerful Elementor addon with advanced Elementor widgets, templates, WooCommerce widgets & Header-Footer builder to build professional websites fa …
Premium Addons for Elementor – Powerful Elementor Templates & Widgets
premium-addons-for-elementor
Elementor Carousel, Mega Menu, Posts List/Slider, Media Gallery, WooCommerce Widgets, Display Conditions, Premade Templates & more.
Royal Addons for Elementor – Addons and Templates Kit for Elementor
royal-elementor-addons
Elementor templates, Header footer builder, Elementor Post Grid, Woocommerce Grid builder, Slider, Forms, Gallery, Nav menu addons, Elementor widgets.
OSM Map Widget for Elementor Developer Profile
1 plugin · 9K total installs
How We Detect OSM Map Widget for Elementor
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/osm-map-elementor/assets/css/admin.cssosm-map-elementor/assets/css/admin.css?ver=HTML / DOM Fingerprints
osm-map-settingsosm-map-elementor<!-- Inline styles for the osm-map widget --><!-- Add inline styles to the osm-map widget --><!-- Elementor Frontend Addon --><!-- Frontend Styles -->+6 morename="osm_widget[gmaps_key]"name="osm_widget[mapbox_token]"name="osm_widget[geoapify_key]"name="osm_widget[enable_fontawesome]"name="osm_widget[osm_custom]"name="osm_widget[osm_custom_attribution]"+1 moreOSM_MAP_SLUGOSM_MAP_VERSIONosm_widget_options