
PulseMaps Visitor World Map Security & Risk Analysis
wordpress.org/plugins/pulsemapsShow off your website visitors on the world map. When people around the world visit your blog, the corresponding areas on the heat map widget light up …
Is PulseMaps Visitor World Map Safe to Use in 2026?
Generally Safe
Score 85/100PulseMaps Visitor World Map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "pulsemaps" plugin version 1.7.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding database interactions, with 100% of SQL queries using prepared statements, and it has no recorded vulnerability history, suggesting a relatively stable and secure past. The absence of bundled libraries also removes a potential vector for outdated and vulnerable third-party code.
However, significant concerns arise from the static analysis. The plugin possesses an unprotected AJAX handler, which represents a direct entry point for potential attackers without any authorization checks. Furthermore, the code signals a dangerous function usage with `create_function`, and a concerningly low rate of output escaping (only 3% properly escaped) indicates a high likelihood of Cross-Site Scripting (XSS) vulnerabilities. The taint analysis, while showing no critical or high severity flows, did identify a flow with unsanitized paths, which could be a precursor to more severe issues if exploited in conjunction with other weaknesses.
Overall, while the lack of historical vulnerabilities is a positive indicator, the presence of an unprotected AJAX endpoint, the use of a dangerous function, and the poor output escaping are critical weaknesses that significantly elevate the risk profile of this plugin. These issues demand immediate attention and remediation.
Key Concerns
- Unprotected AJAX handler
- Dangerous function create_function used
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
- Flow with unsanitized paths found
PulseMaps Visitor World Map Security Vulnerabilities
PulseMaps Visitor World Map Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
PulseMaps Visitor World Map Attack Surface
AJAX Handlers 1
Shortcodes 1
WordPress Hooks 8
Scheduled Events 1
Maintenance & Trust
PulseMaps Visitor World Map Maintenance & Trust
Maintenance Signals
Community Trust
PulseMaps Visitor World Map Alternatives
Plugin Name: Traffic Counter Widget Plugin
traffic-counter-widget
TCW lets your users know how much traffic you have on your blog. It counts pages visited, hits and unique IPs on your blog and shows it in a widget.
Plugin Name: Traffic Stats Widget Plugin
traffic-stats-widget
TSW lets your users know how much traffic you have on your blog. It counts pages visited, hits and unique IPs on your blog and shows it in a widget.
MapGeo – Interactive Geo Maps
interactive-geo-maps
Create interactive vector maps of the world, continents, any country in the world and specific regions, including individual US state county maps.
Mechanic Visitor Counter
mechanic-visitor-counter
Mechanic Visitor Counter is a widgets which will display the Visitor counter and traffic statistics on WordPress. Some of the features offered include …
Crazy Egg
crazyegg-heatmap-tracking
The easiest, free way to add your Crazy Egg tracking script to your WordPress site. The official Crazy Egg Plugin for WordPress.
PulseMaps Visitor World Map Developer Profile
1 plugin · 90 total installs
How We Detect PulseMaps Visitor World Map
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/pulsemaps/css/style.css/wp-content/plugins/pulsemaps/css/widget.css/wp-content/plugins/pulsemaps/js/pulsemaps.jshttp://pulsemaps.com/tracker.js?id=http://pulsemaps.com/map.js?id=pulsemaps/style.css?ver=pulsemaps/pulsemaps.js?ver=HTML / DOM Fingerprints
pulsemaps-map-containerid="pulsemaps_map"pulsemaps_url<div id="pulsemaps_map"Website visitor map by PulseMaps.com</a>