
PlacePress Security & Risk Analysis
wordpress.org/plugins/placepressAn elegant mapping solution for public historians, urbanists, and other humanities researchers.
Is PlacePress Safe to Use in 2026?
Generally Safe
Score 100/100PlacePress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The PlacePress plugin v1.4.96 exhibits a strong security posture based on the provided static analysis. The complete absence of identified attack surface points (AJAX handlers, REST API routes, shortcodes, cron events) is highly commendable, indicating a minimal exposure to external manipulation. Furthermore, the analysis shows no dangerous functions, raw SQL queries, or file operations, and a complete lack of external HTTP requests. The presence of capability checks (3 instances) suggests some attention to authorization, although the lack of nonce checks across any entry points is a notable omission, especially if any hidden or unintended entry points exist.
The taint analysis reports zero flows, which is a positive indicator that sensitive data is not being processed in an insecure manner. The vulnerability history being completely clean (0 CVEs) also points to a plugin that has historically been maintained securely or has not attracted malicious attention. The significant percentage of properly escaped output (57%) is a concern, as a substantial portion (43%) could potentially lead to cross-site scripting (XSS) vulnerabilities if the unescaped data is rendered in a user-facing context without further sanitization.
In conclusion, PlacePress v1.4.96 demonstrates good security practices by minimizing its attack surface and avoiding common pitfalls like raw SQL. However, the unescaped output presents a tangible risk, and the absence of nonce checks, while not directly evidenced as exploitable due to the lack of identified entry points, represents a potential weakness. The clean vulnerability history is a strong positive, but the output escaping issue should be addressed to solidify its security.
Key Concerns
- Significant portion of output not properly escaped
- Missing nonce checks
PlacePress Security Vulnerabilities
PlacePress Release Timeline
PlacePress Code Analysis
Output Escaping
PlacePress Attack Surface
WordPress Hooks 27
Maintenance & Trust
PlacePress Maintenance & Trust
Maintenance Signals
Community Trust
PlacePress Alternatives
Timeline Widget For Elementor (Elementor Timeline, Vertical & Horizontal Timeline)
timeline-widget-addon-for-elementor
Highlight your company’s history, milestones, and key events directly inside Elementor using stunning vertical and horizontal timelines.
Cool Timeline (Horizontal & Vertical Timeline)
cool-timeline
Showcase your story or company history, events, and roadmap in an interactive timeline using the powerful Cool Timeline plugin.
Timeline Block For Gutenberg
timeline-block
Showcase your company history, process steps, milestones, and roadmap inside Gutenberg using the powerful Timeline Block
Timeline Module for Divi
timeline-module-for-divi
Highlight your company's history, milestones, and future plans with the advanced Timeline Module for Divi.
Ultimate Timeline – Responsive History Timeline
ultimate-timeline
Ultimate Timeline plugin creates beautiful history time-lines on your website. It is responsive time-line showcase in DESC order based on posted date …
PlacePress Developer Profile
1 plugin · 30 total installs
How We Detect PlacePress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/placepress/javascripts/leaflet@1.9.3/leaflet.css/wp-content/plugins/placepress/javascripts/leaflet@1.9.3/leaflet.js/wp-content/plugins/placepress/javascripts/leaflet.markercluster@1.4.1/MarkerCluster.css/wp-content/plugins/placepress/javascripts/leaflet.markercluster@1.4.1/MarkerCluster.Default.css/wp-content/plugins/placepress/javascripts/leaflet.markercluster@1.4.1/leaflet.markercluster.js/wp-content/plugins/placepress/placepress-blocks/src/tile-provider.js/wp-content/plugins/placepress/placepress-blocks/src/placepress.js/wp-content/plugins/placepress/admin/settings/settings.js+1 more/wp-content/plugins/placepress/placepress-blocks/src/placepress.js/wp-content/plugins/placepress/admin/settings/settings.jsHTML / DOM Fingerprints
placepress-map-containerdata-placepress-settingdata-placepress-map-idplacepress_scripts_vars