Photo Map Embed Security & Risk Analysis

wordpress.org/plugins/photo-map-embed

Short Description: Turn EXIF GPS into an interactive map. Gutenberg block and shortcode. Edit pin titles; embed in seconds. No image uploads.

0 active installs v0.4.4 PHP 7.4+ WP 5.8+ Updated Unknown
exif-gpsgutenberg-blockleafletmapsphoto-embed
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Photo Map Embed Safe to Use in 2026?

Generally Safe

Score 100/100

Photo Map Embed has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "photo-map-embed" plugin version 0.4.4 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, SQL queries without prepared statements, file operations, external HTTP requests, and known vulnerabilities is highly positive. The plugin also demonstrates good practices by having a capability check in place. However, the analysis does reveal areas for improvement that could increase its security. Specifically, the lack of nonce checks on its two shortcodes presents a potential avenue for cross-site request forgery (CSRF) attacks if those shortcodes perform any sensitive actions, though the analysis indicates no direct entry points without authentication checks.

Key Concerns

  • Shortcodes lack nonce checks
  • Output escaping not fully implemented (27% unescaped)
Vulnerabilities
None known

Photo Map Embed Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Photo Map Embed Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
29
80 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

73% escaped109 total outputs
Attack Surface

Photo Map Embed Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[photomapembed] photo-map-embed.php:163
[photomap] photo-map-embed.php:164
WordPress Hooks 3
actionadmin_menuincludes\settings-page.php:25
actionadmin_enqueue_scriptsphoto-map-embed.php:175
actioninitphoto-map-embed.php:234
Maintenance & Trust

Photo Map Embed Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version7.4
Downloads223

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Photo Map Embed Developer Profile

ahninternational

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Photo Map Embed

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/photo-map-embed/assets/admin.css/wp-content/plugins/photo-map-embed/assets/admin.js/wp-content/plugins/photo-map-embed/assets/blocks.js
Script Paths
/wp-content/plugins/photo-map-embed/assets/admin.js/wp-content/plugins/photo-map-embed/assets/blocks.js
Version Parameters
photo-map-embed/assets/admin.js?ver=photo-map-embed/assets/admin.css?ver=photo-map-embed/assets/blocks.js?ver=

HTML / DOM Fingerprints

CSS Classes
pmem-embed-wrappmem-helperpmem-error
Data Attributes
data-iddata-markersdata-viewdata-styledata-widthdata-height+1 more
JS Globals
pmemDefaults
Shortcode Output
<div class="pmem-helper" style="border:1px solid #e5e7eb;border-radius:12px;padding:16px;background:#f8fafc;"><div class="pmem-error">Photo Map Embed: invalid markers JSON.</div><div class="pmem-error">Photo Map Embed: invalid view JSON.</div>
FAQ

Frequently Asked Questions about Photo Map Embed