
Photo Map Embed Security & Risk Analysis
wordpress.org/plugins/photo-map-embedShort Description: Turn EXIF GPS into an interactive map. Gutenberg block and shortcode. Edit pin titles; embed in seconds. No image uploads.
Is Photo Map Embed Safe to Use in 2026?
Generally Safe
Score 100/100Photo Map Embed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "photo-map-embed" plugin version 0.4.4 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, SQL queries without prepared statements, file operations, external HTTP requests, and known vulnerabilities is highly positive. The plugin also demonstrates good practices by having a capability check in place. However, the analysis does reveal areas for improvement that could increase its security. Specifically, the lack of nonce checks on its two shortcodes presents a potential avenue for cross-site request forgery (CSRF) attacks if those shortcodes perform any sensitive actions, though the analysis indicates no direct entry points without authentication checks.
Key Concerns
- Shortcodes lack nonce checks
- Output escaping not fully implemented (27% unescaped)
Photo Map Embed Security Vulnerabilities
Photo Map Embed Code Analysis
Output Escaping
Photo Map Embed Attack Surface
Shortcodes 2
WordPress Hooks 3
Maintenance & Trust
Photo Map Embed Maintenance & Trust
Maintenance Signals
Community Trust
Photo Map Embed Alternatives
MapPress Maps for WordPress
mappress-google-maps-for-wordpress
MapPress is the easiest way to add unlimited interactive Google and Leaflet maps to WordPress.
Map Block for Google Maps
map-block-gutenberg
Map block for Gutenberg editor powered by Google Maps. Simple. Fast. Just a map block.
Out of the Block: OpenStreetMap
ootb-openstreetmap
A map block for Gutenberg using OpenStreetMap and Leaflet that needs no API keys and works out of the box. Or should we say, ...Out of the Block?
BS Maps – Google Map and Leaflet Map for Elementor and WPBackery
bs-maps-google-map-and-leaflet-map-for-elementor-and-wpbakery
The easiest to use Google maps and Leaflet maps addons for Elementor and Wp Backery! Create a custom Google map and Leaflet maps with Elementor and Wp …
Easy Map – Store Locator, Google Maps, OpenStreetMap, Leaflet Map
easy-map
Create interactive maps with store locator, markers, drawings & multiple locations. Supports OpenStreetMap and Google Maps. No API key needed.
Photo Map Embed Developer Profile
1 plugin · 0 total installs
How We Detect Photo Map Embed
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/photo-map-embed/assets/admin.css/wp-content/plugins/photo-map-embed/assets/admin.js/wp-content/plugins/photo-map-embed/assets/blocks.js/wp-content/plugins/photo-map-embed/assets/admin.js/wp-content/plugins/photo-map-embed/assets/blocks.jsphoto-map-embed/assets/admin.js?ver=photo-map-embed/assets/admin.css?ver=photo-map-embed/assets/blocks.js?ver=HTML / DOM Fingerprints
pmem-embed-wrappmem-helperpmem-errordata-iddata-markersdata-viewdata-styledata-widthdata-height+1 morepmemDefaults<div class="pmem-helper" style="border:1px solid #e5e7eb;border-radius:12px;padding:16px;background:#f8fafc;"><div class="pmem-error">Photo Map Embed: invalid markers JSON.</div><div class="pmem-error">Photo Map Embed: invalid view JSON.</div>