
Pronamic Google Maps Security & Risk Analysis
wordpress.org/plugins/pronamic-google-mapsThis plugin makes it easy to add Google Maps to your WordPress post, pages or other custom post types.
Is Pronamic Google Maps Safe to Use in 2026?
Generally Safe
Score 98/100Pronamic Google Maps has a strong security track record. Known vulnerabilities have been patched promptly.
The pronamic-google-maps v2.4.2 plugin exhibits a generally good security posture with several strengths. Notably, all SQL queries are properly prepared, and the vast majority of output is correctly escaped, significantly mitigating common injection and XSS risks. The absence of dangerous functions, file operations, and bundled libraries is also positive. However, there are a few areas of concern. The presence of one unprotected AJAX handler presents a potential entry point for attackers if not properly secured at the application or server level. The plugin's history of two medium-severity CVEs, specifically related to Cross-Site Scripting, is a significant indicator that input sanitization and output escaping, despite the current high rate of proper escaping, may have been insufficient in past versions and warrants continued vigilance. While no current unpatched vulnerabilities are listed, the historical pattern suggests a recurring weakness in handling user-supplied data, which could be exploited if similar coding patterns persist.
Key Concerns
- Unprotected AJAX handler found
- Two historical medium CVEs for XSS
Pronamic Google Maps Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Pronamic Google Maps <= 2.4.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Pronamic Google Maps <= 2.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Pronamic Google Maps Code Analysis
SQL Query Safety
Output Escaping
Pronamic Google Maps Attack Surface
AJAX Handlers 1
Shortcodes 4
WordPress Hooks 10
Maintenance & Trust
Pronamic Google Maps Maintenance & Trust
Maintenance Signals
Community Trust
Pronamic Google Maps Alternatives
Basic Google Maps Placemarks
basic-google-maps-placemarks
Embeds a Google Map into your site and lets you add map markers with custom icons and information windows.
WP Job Manager Client-Side Geocoder
wp-job-manager-client-side-geocoder
Use client-side geocoding to overcome the OVER_QUERY_LIMIT ( failed to geocode a location ) issue when updating job's location
Oppso Maps
oppso-maps
Add a Google Map to your wordpress site! Oppso Maps creates a map shortcode to use in posts, pages or text widgets.
Store Locator for WordPress Posts
wp-post-store-locator
This is a wordpress store locator plugin for posts. We can setup stores for individual posts/products.
Geo Mashup
geo-mashup
Include Google and OpenStreetMap maps in posts and pages, and map posts, pages, and other objects on global maps. Make WordPress into a GeoCMS.
Pronamic Google Maps Developer Profile
15 plugins · 5K total installs
How We Detect Pronamic Google Maps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pronamic-google-maps/js/admin.js/wp-content/plugins/pronamic-google-maps/css/admin.cssjs/admin.jsHTML / DOM Fingerprints
pronamic-google-maps-adminpronamic-google-maps-metaboxpronamic-google-maps-mapdata-pronamic-google-maps-activedata-pronamic-google-maps-latitudedata-pronamic-google-maps-longitudedata-pronamic-google-maps-map-typedata-pronamic-google-maps-zoomdata-pronamic-google-maps-title+2 morepronamic_google_maps_settings/wp-json/pronamic-google-maps/v1/geocode[pronamic_google_maps