
PeproDev Branches Map Security & Risk Analysis
wordpress.org/plugins/pepro-mapifyList your branches on a beautiful map with clickable hotspots, supporting 70+ Google Maps custom styles, and integrates into WPBakery Page Builder
Is PeproDev Branches Map Safe to Use in 2026?
Generally Safe
Score 85/100PeproDev Branches Map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The pepro-mapify plugin version 1.3.6 demonstrates a generally strong security posture based on the provided static analysis. A notable strength is the absence of dangerous functions, file operations, external HTTP requests, and SQL queries that do not utilize prepared statements. The plugin also has no recorded vulnerabilities (CVEs), which is a very positive indicator of its security history. This suggests diligent development and a lack of publicly known exploits.
However, there are areas for concern. The plugin exhibits a low percentage (49%) of properly escaped output, indicating a potential for cross-site scripting (XSS) vulnerabilities, especially if the unescaped outputs handle user-supplied data. Furthermore, the complete absence of nonce checks and capability checks across all identified entry points (even though the attack surface is small) is a significant weakness. This lack of authorization checks on its single shortcode means that any user, regardless of their role or privileges, could potentially trigger its functionality, opening the door to unauthorized actions or information disclosure if the shortcode's processing is not inherently secure.
In conclusion, while the plugin benefits from a clean vulnerability history and secure handling of sensitive operations like SQL and file access, the lack of output escaping and, more critically, the absence of proper authorization checks on its entry points represent real security risks that need to be addressed. The strengths in secure coding practices for certain areas are unfortunately overshadowed by the vulnerabilities in input validation and authorization.
Key Concerns
- Unescaped output (51% not properly escaped)
- No nonce checks on entry points
- No capability checks on entry points
PeproDev Branches Map Security Vulnerabilities
PeproDev Branches Map Code Analysis
Output Escaping
PeproDev Branches Map Attack Surface
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
PeproDev Branches Map Maintenance & Trust
Maintenance Signals
Community Trust
PeproDev Branches Map Alternatives
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)
leaflet-maps-marker
The most comprehensive & user-friendly mapping solution for WordPress
Interactive World Map
interactive-world-map
Free plugin for WordPress displays an interactive map of the World. The map features customized colors, links and popup balloons.
MW Google Maps
mw-google-maps
MW Google Maps adds google maps in your post easy.
Interactive World, Europe & US Maps – Atlas Maps
atlas-maps
Build interactive world, Europe & US maps with clickable regions, tooltips and pins. Responsive map plugin for WordPress, no coding required.
indomap
indomap
jQuery plugin to create google maps with advanced features (overlays, clusters, callbacks, events...)
PeproDev Branches Map Developer Profile
6 plugins · 8K total installs
How We Detect PeproDev Branches Map
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pepro-mapify/assets/app/metabx.php/wp-content/plugins/pepro-mapify/assets/css/branches-single.css/wp-content/plugins/pepro-mapify/assets/js/vc.init.js/wp-content/plugins/pepro-mapify/assets/js/pin.maker.js/wp-content/plugins/pepro-mapify/assets/js/vc.init.js/wp-content/plugins/pepro-mapify/assets/js/pin.maker.jspepro-mapify/assets/js/vc.init.js?ver=pepro-mapify/assets/js/pin.maker.js?ver=HTML / DOM Fingerprints
pepro-branches-map-wrapperbranches-cpt-titlebranches-cpt-addressbranches-cpt-phonebranches-cpt-websitebranches-cpt-emailbranches-cpt-socialicon-social+2 more<!-- @Last modified by: Amirhosseinhpv --><!-- @Last modified time: 2021/03/27 17:09:32 -->data-post-iddata-post-typepepro_mapify_datapepro_branchespepro_mapify_map_optionspepro_mapify_pin_optionspepro_mapify_styles/wp-json/pepro-mapify/v1/settings/wp-json/pepro-mapify/v1/get-branches[pepro-mapify][pepro_mapify_branch][pepro_mapify_branches]