Sales Map for Woocommerce Security & Risk Analysis

wordpress.org/plugins/sales-map-for-woocommerce

Sales Map for WooCommerce is a plugin that shows sales in a google map with shortcode. By installing this plugin, you can see which parts of the world …

10 active installs v1.0.0 PHP 5.4+ WP 3.0.1+ Updated May 28, 2021
mapordersales
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Sales Map for Woocommerce Safe to Use in 2026?

Generally Safe

Score 85/100

Sales Map for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4yr ago
Risk Assessment

The "sales-map-for-woocommerce" plugin, in version 1.0.0, exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and has no recorded vulnerabilities in its history, suggesting a generally well-maintained codebase. However, significant concerns arise from its attack surface. The plugin exposes two AJAX handlers, both of which lack authentication checks, creating potential entry points for unauthorized actions. Furthermore, a substantial portion of its output (50%) is not properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without sanitization. The absence of nonce checks on AJAX actions is a critical oversight that exacerbates the risk of CSRF attacks.

While the lack of dangerous functions, file operations, and external HTTP requests are positive indicators, the unprotected AJAX endpoints and the unescaped output are substantial weaknesses. The plugin's vulnerability history being completely clean is encouraging, but it does not negate the immediate risks identified in the static analysis. The overall conclusion is that while the plugin has a clean past, its current version has critical security flaws, particularly concerning the unprotected AJAX handlers and the risk of XSS through unescaped output, which require urgent attention.

Key Concerns

  • AJAX handlers without auth checks
  • Unescaped output (50%)
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Sales Map for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Sales Map for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

50% escaped8 total outputs
Attack Surface
2 unprotected

Sales Map for Woocommerce Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_sgitswcsm_latlngincludes\class-sales-map-woo.php:184
noprivwp_ajax_sgitswcsm_latlngincludes\class-sales-map-woo.php:185

Shortcodes 1

[sgitswcsm] includes\class-sales-map-woo.php:183
WordPress Hooks 9
actionplugins_loadedincludes\class-sales-map-woo.php:144
actionadmin_enqueue_scriptsincludes\class-sales-map-woo.php:159
actionadmin_enqueue_scriptsincludes\class-sales-map-woo.php:160
filterwoocommerce_get_sections_advancedincludes\class-sales-map-woo.php:162
filterwoocommerce_get_settings_advancedincludes\class-sales-map-woo.php:163
filterplugin_row_metaincludes\class-sales-map-woo.php:165
actionwp_enqueue_scriptsincludes\class-sales-map-woo.php:180
actionwp_enqueue_scriptsincludes\class-sales-map-woo.php:181
actionwoocommerce_new_orderincludes\class-sales-map-woo.php:182
Maintenance & Trust

Sales Map for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested5.7.15
Last updatedMay 28, 2021
PHP min version5.4
Downloads961

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Sales Map for Woocommerce Developer Profile

Sarankumar

12 plugins · 3K total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Sales Map for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/sales-map-for-woocommerce/admin/css/sales-map-woo-admin.css/wp-content/plugins/sales-map-for-woocommerce/admin/js/sales-map-woo-admin.js
Version Parameters
sales-map-for-woocommerce/admin/css/sales-map-woo-admin.css?ver=sales-map-for-woocommerce/admin/js/sales-map-woo-admin.js?ver=

HTML / DOM Fingerprints

Data Attributes
sgitswcsm_settings_tab
Shortcode Output
[sgitswcsm]
FAQ

Frequently Asked Questions about Sales Map for Woocommerce