
RockScience Marine Chart Viewer for NOAA ENC Security & Risk Analysis
wordpress.org/plugins/rockscience-enc-chart-viewer-for-noaaEmbed interactive NOAA nautical charts using official government APIs. Covers U.S. waters, Great Lakes, and territories.
Is RockScience Marine Chart Viewer for NOAA ENC Safe to Use in 2026?
Generally Safe
Score 100/100RockScience Marine Chart Viewer for NOAA ENC has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "rockscience-enc-chart-viewer-for-noaa" plugin version 2025.09.1 exhibits a strong security posture based on the provided static analysis. The complete absence of dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and the use of prepared statements for all SQL queries are commendable practices. Furthermore, the lack of any recorded vulnerabilities in its history suggests a history of responsible development and maintenance. The limited attack surface, primarily consisting of a single shortcode with no immediate indication of missing security checks, further reinforces this positive assessment.
However, the static analysis data does reveal a significant area of concern: the complete absence of nonce checks and capability checks across all identified entry points. While the number of entry points is small, relying solely on WordPress's default protections without explicit checks can leave the plugin vulnerable to cross-site request forgery (CSRF) attacks if the shortcode's functionality is sensitive or can be leveraged to perform privileged actions. The taint analysis showing zero flows is positive but does not negate the potential risks associated with missing explicit security controls. The vulnerability history is a strength, but the lack of specific security checks on the single identified entry point is a potential weakness that warrants attention.
In conclusion, the plugin demonstrates excellent coding practices in many areas, but the oversight in implementing nonce and capability checks for its shortcode presents a notable security risk. While there are no known vulnerabilities or critical static analysis findings, this missing layer of protection could be exploited. The plugin's strengths lie in its clean code and lack of historical security issues, but the identified gap in authentication/authorization checks is a weakness that should be addressed to ensure a more robust security profile.
Key Concerns
- Missing nonce checks on shortcode
- Missing capability checks on shortcode
RockScience Marine Chart Viewer for NOAA ENC Security Vulnerabilities
RockScience Marine Chart Viewer for NOAA ENC Code Analysis
Output Escaping
RockScience Marine Chart Viewer for NOAA ENC Attack Surface
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
RockScience Marine Chart Viewer for NOAA ENC Maintenance & Trust
Maintenance Signals
Community Trust
RockScience Marine Chart Viewer for NOAA ENC Alternatives
Visualizer: Tables and Charts Manager for WordPress
visualizer
A simple yet powerful WordPress chart plugin to effortlessly create and embed responsive charts & tables into your site, supporting multiple data …
Graphina – Charts and Graphs For Elementor
graphina-elementor-charts-and-graphs
Most Powerful Data visualization plugin for WordPress Elementor. The easiest way to build gorgeous Charts & Graphs on your Elementor website.
Chartify – WordPress Chart Plugin
chart-builder
Chartify is a powerful WordPress Chart Builder Plugin that will help you to create WordPress Graphs & Charts easily and quickly.
M Chart
m-chart
Manage data sets and display them as charts in WordPress.
Ninja Charts – Interactive Charts and Graphs
ninja-charts
The easiest way to create responsive, customizable, and reusable charts and graphs for your website.
RockScience Marine Chart Viewer for NOAA ENC Developer Profile
1 plugin · 0 total installs
How We Detect RockScience Marine Chart Viewer for NOAA ENC
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/rockscience-enc-chart-viewer-for-noaa/css/style.css/wp-content/plugins/rockscience-enc-chart-viewer-for-noaa/js/chart-core-api.jshttps://js.arcgis.com/4.31/esri/themes/light/main.csshttps://js.arcgis.com/4.31/rockscience-enc-chart-viewer-for-noaa/css/style.css?ver=rockscience-enc-chart-viewer-for-noaa/js/chart-core-api.js?ver=HTML / DOM Fingerprints
cvldata-rs-enc-chart-optionswindow.rockscienceEncChartDefaults<div id="rockscience_enc_map_"<div style="border: 2px solid red; padding: 10px; background: #ffe6e6;"><strong>Chart Error:</strong><br>