Progus Store Locator Map (No API Key Required) Security & Risk Analysis

wordpress.org/plugins/progus-store-locator

Powerful Store, Dealer & Stockist Locator with all features for just $3.99/month. Trusted by 4,000+ businesses worldwide.

10 active installs v1.0.1 PHP 7.4+ WP 5.0+ Updated Feb 19, 2026
dealer-locatorgoogle-mapsmapstockiststore-locator
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Progus Store Locator Map (No API Key Required) Safe to Use in 2026?

Generally Safe

Score 100/100

Progus Store Locator Map (No API Key Required) has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The progus-store-locator plugin v1.0.1 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and the plugin's adherence to using prepared statements for SQL queries are strong positive indicators. Furthermore, the limited attack surface and the presence of capability checks on its entry points suggest a reasonable effort towards secure development. However, a notable concern arises from the relatively low percentage of properly escaped output. With only 33% of 40 outputs being properly escaped, there's a significant potential for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is rendered without adequate sanitization. While taint analysis found no flows, this could be due to the analysis scope or the plugin not handling user input in ways that would trigger taint detection in this specific analysis. The presence of external HTTP requests also warrants careful consideration, as these could be a vector for certain types of attacks if not handled securely. Overall, the plugin has a solid foundation but requires attention to output sanitization to mitigate XSS risks.

Key Concerns

  • Low percentage of properly escaped output
  • External HTTP requests present
Vulnerabilities
None known

Progus Store Locator Map (No API Key Required) Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Progus Store Locator Map (No API Key Required) Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
27
13 escaped
Nonce Checks
1
Capability Checks
3
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

33% escaped40 total outputs
Attack Surface

Progus Store Locator Map (No API Key Required) Attack Surface

Entry Points5
Unprotected0

REST API Routes 5

GET/wp-json/progus-store-locator/v1/get-url/(?P<id>\d+)progus-store-locator.php:238
POST/wp-json/progus-store-locator/v1/update-slug/(?P<id>\d+)progus-store-locator.php:251
POST/wp-json/progus-store-locator/v1/update-title/(?P<id>\d+)progus-store-locator.php:271
POST/wp-json/progus-store-locator/v1/update-status/(?P<id>\d+)progus-store-locator.php:291
POST/wp-json/progus-store-locator/v1/create-pageprogus-store-locator.php:312
WordPress Hooks 3
actionwp_privacy_policy_contentincludes\privacy.class.php:32
filterwp_privacy_personal_data_exportersincludes\privacy.class.php:33
filterwp_privacy_personal_data_erasersincludes\privacy.class.php:34
Maintenance & Trust

Progus Store Locator Map (No API Key Required) Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 19, 2026
PHP min version7.4
Downloads373

Community Trust

Rating100/100
Number of ratings5
Active installs10
Developer Profile

Progus Store Locator Map (No API Key Required) Developer Profile

progus

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Progus Store Locator Map (No API Key Required)

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/progus-store-locator/includes/js/components/map.js/wp-content/plugins/progus-store-locator/includes/js/components/search.js/wp-content/plugins/progus-store-locator/includes/js/app.js/wp-content/plugins/progus-store-locator/includes/js/admin.js/wp-content/plugins/progus-store-locator/includes/css/map.css
Script Paths
block.js
Version Parameters
progus-store-locator/includes/css/map.css?ver=progus-store-locator/includes/js/app.js?ver=progus-store-locator/includes/js/admin.js?ver=progus-store-locator/block.js?ver=

HTML / DOM Fingerprints

CSS Classes
psl-map-containerpsl-search-containerpsl-store-locator-widget
Data Attributes
data-psl-map-urldata-psl-form-url
JS Globals
blockData
REST Endpoints
/wp-json/progus-store-locator/v1/get-url//wp-json/progus-store-locator/v1/update-slug/
Shortcode Output
[store_locator][store_locator_map][store_locator_search]
FAQ

Frequently Asked Questions about Progus Store Locator Map (No API Key Required)