PeproDev Branches Map Security & Risk Analysis

wordpress.org/plugins/pepro-mapify

List your branches on a beautiful map with clickable hotspots, supporting 70+ Google Maps custom styles, and integrates into WPBakery Page Builder

40 active installs v1.3.6 PHP 5.6+ WP 5.0+ Updated Jan 26, 2022
functionalitygooglemapsmapshow-branches-on-mapsvg-map
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is PeproDev Branches Map Safe to Use in 2026?

Generally Safe

Score 85/100

PeproDev Branches Map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The pepro-mapify plugin version 1.3.6 demonstrates a generally strong security posture based on the provided static analysis. A notable strength is the absence of dangerous functions, file operations, external HTTP requests, and SQL queries that do not utilize prepared statements. The plugin also has no recorded vulnerabilities (CVEs), which is a very positive indicator of its security history. This suggests diligent development and a lack of publicly known exploits.

However, there are areas for concern. The plugin exhibits a low percentage (49%) of properly escaped output, indicating a potential for cross-site scripting (XSS) vulnerabilities, especially if the unescaped outputs handle user-supplied data. Furthermore, the complete absence of nonce checks and capability checks across all identified entry points (even though the attack surface is small) is a significant weakness. This lack of authorization checks on its single shortcode means that any user, regardless of their role or privileges, could potentially trigger its functionality, opening the door to unauthorized actions or information disclosure if the shortcode's processing is not inherently secure.

In conclusion, while the plugin benefits from a clean vulnerability history and secure handling of sensitive operations like SQL and file access, the lack of output escaping and, more critically, the absence of proper authorization checks on its entry points represent real security risks that need to be addressed. The strengths in secure coding practices for certain areas are unfortunately overshadowed by the vulnerabilities in input validation and authorization.

Key Concerns

  • Unescaped output (51% not properly escaped)
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

PeproDev Branches Map Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

PeproDev Branches Map Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
25
24 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

49% escaped49 total outputs
Attack Surface

PeproDev Branches Map Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[pepro-mapify] pepro-mapify.php:86
WordPress Hooks 12
actioninitpepro-mapify.php:66
actionvc_before_initpepro-mapify.php:71
actionplugin_row_metapepro-mapify.php:81
actionadmin_menupepro-mapify.php:82
actionadmin_initpepro-mapify.php:83
actionadmin_enqueue_scriptspepro-mapify.php:84
actionadmin_print_footer_scriptspepro-mapify.php:85
filterthe_contentpepro-mapify.php:88
filterpost_updated_messagespepro-mapify.php:1069
filteradmin_footer_textpepro-mapify.php:1119
filterupdate_footerpepro-mapify.php:1124
actionplugins_loadedpepro-mapify.php:2954
Maintenance & Trust

PeproDev Branches Map Maintenance & Trust

Maintenance Signals

WordPress version tested5.9.13
Last updatedJan 26, 2022
PHP min version5.6
Downloads3K

Community Trust

Rating100/100
Number of ratings1
Active installs40
Developer Profile

PeproDev Branches Map Developer Profile

Pepro Dev. Group

6 plugins · 8K total installs

69
trust score
Avg Security Score
86/100
Avg Patch Time
104 days
View full developer profile
Detection Fingerprints

How We Detect PeproDev Branches Map

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/pepro-mapify/assets/app/metabx.php/wp-content/plugins/pepro-mapify/assets/css/branches-single.css/wp-content/plugins/pepro-mapify/assets/js/vc.init.js/wp-content/plugins/pepro-mapify/assets/js/pin.maker.js
Script Paths
/wp-content/plugins/pepro-mapify/assets/js/vc.init.js/wp-content/plugins/pepro-mapify/assets/js/pin.maker.js
Version Parameters
pepro-mapify/assets/js/vc.init.js?ver=pepro-mapify/assets/js/pin.maker.js?ver=

HTML / DOM Fingerprints

CSS Classes
pepro-branches-map-wrapperbranches-cpt-titlebranches-cpt-addressbranches-cpt-phonebranches-cpt-websitebranches-cpt-emailbranches-cpt-socialicon-social+2 more
HTML Comments
<!-- @Last modified by: Amirhosseinhpv --><!-- @Last modified time: 2021/03/27 17:09:32 -->
Data Attributes
data-post-iddata-post-type
JS Globals
pepro_mapify_datapepro_branchespepro_mapify_map_optionspepro_mapify_pin_optionspepro_mapify_styles
REST Endpoints
/wp-json/pepro-mapify/v1/settings/wp-json/pepro-mapify/v1/get-branches
Shortcode Output
[pepro-mapify][pepro_mapify_branch][pepro_mapify_branches]
FAQ

Frequently Asked Questions about PeproDev Branches Map