
Placemarks Security & Risk Analysis
wordpress.org/plugins/placemarksAllow authors to easily manage placemarks and embed custom maps.
Is Placemarks Safe to Use in 2026?
Generally Safe
Score 85/100Placemarks has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "placemarks" plugin version 3.0.1 presents a generally good security posture with no known vulnerabilities in its history and a limited attack surface. The static analysis indicates no critical or high-severity taint flows, no dangerous functions, and no file operations or external HTTP requests, which are positive indicators. The presence of capability checks suggests some level of access control is implemented.
However, there are notable areas of concern. A significant weakness lies in the handling of SQL queries; the single SQL query identified is not using prepared statements, which is a substantial risk for SQL injection vulnerabilities. Furthermore, the output escaping is notably poor, with only 18% of outputs properly escaped. This, combined with the absence of nonce checks, significantly increases the risk of Cross-Site Scripting (XSS) vulnerabilities, especially given the presence of a shortcode which can be a vector for injecting malicious content.
Overall, while the plugin benefits from a clean vulnerability history and a contained attack surface, the lack of prepared statements for SQL queries and the low percentage of properly escaped output represent critical security flaws that demand immediate attention. The absence of nonce checks further exacerbates the XSS risk.
Key Concerns
- SQL queries not using prepared statements
- Low percentage of properly escaped output
- No nonce checks
Placemarks Security Vulnerabilities
Placemarks Code Analysis
SQL Query Safety
Output Escaping
Placemarks Attack Surface
Shortcodes 1
WordPress Hooks 17
Maintenance & Trust
Placemarks Maintenance & Trust
Maintenance Signals
Community Trust
Placemarks Alternatives
CodePeople Post Map for Google Maps
codepeople-post-map
CodePeople Post Map lets you geotag posts and seamlessly integrate your blog with Google Maps for a smooth, location-aware experience.
Autocomplete Google Address
autocomplete-google-address
Add Google Places address autocomplete to any existing form in WordPress using a selector-based mapping builder.
Basic Google Maps Placemarks
basic-google-maps-placemarks
Embeds a Google Map into your site and lets you add map markers with custom icons and information windows.
Stellar Places
stellar-places
Easily create, manage and display locations in a way that makes sense.
Map Field for Contact Form 7
map-field-for-contact-form-7
Add a Google Maps autocomplete address field with a live interactive map to any Contact Form 7 form. Supports draggable marker, address components, an …
Placemarks Developer Profile
5 plugins · 250 total installs
How We Detect Placemarks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/placemarks/vendor/leaflet/leaflet.css/wp-content/plugins/placemarks/admin/css/placemarks-admin.css/wp-content/plugins/placemarks/public/js/placemarks-public.js/wp-content/plugins/placemarks/vendor/leaflet/leaflet.js/wp-content/plugins/placemarks/public/js/includes/overlay-layer.obj.js/wp-content/plugins/placemarks/admin/js/placemarks-admin.js/wp-content/plugins/placemarks/public/js/placemarks-public.js/wp-content/plugins/placemarks/vendor/leaflet/leaflet.js/wp-content/plugins/placemarks/public/js/includes/overlay-layer.obj.js/wp-content/plugins/placemarks/admin/js/placemarks-admin.js/wp-content/plugins/placemarks/vendor/leaflet/leaflet.css?ver=/wp-content/plugins/placemarks/admin/css/placemarks-admin.css?ver=/wp-content/plugins/placemarks/public/js/placemarks-public.js?ver=/wp-content/plugins/placemarks/vendor/leaflet/leaflet.js?ver=/wp-content/plugins/placemarks/public/js/includes/overlay-layer.obj.js?ver=/wp-content/plugins/placemarks/admin/js/placemarks-admin.js?ver=HTML / DOM Fingerprints
placemarks-latplacemarks-lngplacemarks-locationplacemarks-locationsplacemarks-typeplacemarks-title+2 morejsonp_tilesjsonp_locationsjsonp_types/placemarks/v2/settings