
Pimap Security & Risk Analysis
wordpress.org/plugins/pimapA plugin that allows users to record information that will be displayed on the google maps pins.
Is Pimap Safe to Use in 2026?
Generally Safe
Score 100/100Pimap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pimap" v1.2.0 plugin presents a mixed security posture. On one hand, the static analysis indicates a good adherence to some security best practices, with no detected dangerous functions, all SQL queries using prepared statements, and a complete absence of external HTTP requests and file operations. The plugin also implements a reasonable number of capability checks (4) and nonce checks (2), suggesting an effort to protect certain functionalities.
However, there are significant areas of concern. The most prominent is the high percentage of improperly escaped output (65%). This is a critical vulnerability vector, as it can lead to Cross-Site Scripting (XSS) attacks if user-supplied data is not properly sanitized before being displayed. Additionally, the taint analysis reveals 3 flows with unsanitized paths, indicating potential for injection vulnerabilities. While the severity is not explicitly categorized as critical or high, unsanitized paths are a direct pathway to exploits. The absence of unpatched CVEs and past vulnerabilities is a positive sign, but it does not negate the present code-level risks.
In conclusion, while "pimap" v1.2.0 demonstrates strengths in its handling of SQL and external interactions, the substantial amount of unescaped output and the presence of unsanitized paths in the taint analysis represent significant security weaknesses that require immediate attention to mitigate XSS and other injection-related risks.
Key Concerns
- High percentage of unescaped output
- Taint flows with unsanitized paths
Pimap Security Vulnerabilities
Pimap Code Analysis
Output Escaping
Data Flow Analysis
Pimap Attack Surface
Shortcodes 27
WordPress Hooks 25
Maintenance & Trust
Pimap Maintenance & Trust
Maintenance Signals
Community Trust
Pimap Alternatives
flodjiContacts
flodjicontacts-lite
So wirds benutzt: <code>[contact-box]</code> Dazu gibt es dann unter jedem Artikel eine Metabox über die die Contact Box befüllt wird.
Simple Map
simple-map
Easy way to embed google map(s).
Simple Shortcode for Google Maps
simple-google-maps-short-code
A simple shortcode for embedding Google Maps in any WordPress post, page or widget.
WooReer
wcsdm
WooReer calculates shipping rates based on distance via Google Maps, Mapbox, DistanceMatrix.ai, Geoapify, or HERE.
Calculate Prices based on Distance For WooCommerce
calculate-prices-based-on-distance-for-woocommerce
The best WooCommerce Distance Rate Shipping alternative. Secure delivery fee calculation by KM/Mile via Google Maps. Supports Block Checkout & Del …
Pimap Developer Profile
7 plugins · 840 total installs
How We Detect Pimap
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pimap/assets/css/style.css/wp-content/plugins/pimap/assets/js/gmaps.js/wp-content/plugins/pimap/assets/js/infobox.js/wp-content/plugins/pimap/assets/js/gmaps_view.jshttps://maps.google.com/maps/api/js/wp-content/plugins/pimap/assets/js/gmaps.js/wp-content/plugins/pimap/assets/js/infobox.js/wp-content/plugins/pimap/assets/js/gmaps_view.jsHTML / DOM Fingerprints
pimap_mapsdata-pimap_latitudedata-pimap_longitudedata-pimap_zoomdata_pimap_postdata_pimap<div id="pimap_gMaps" class="pimap_maps" style="height:500px; width: 100%"></div>