
Slick Google Map Security & Risk Analysis
wordpress.org/plugins/slick-google-mapA simple and intuitive, yet elegant and fully documented Google map plugin that installs as a widget and a short code.
Is Slick Google Map Safe to Use in 2026?
Use With Caution
Score 63/100Slick Google Map has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The "slick-google-map" v0.3 plugin presents a moderate security risk. While it shows some positive signs like a relatively low number of external HTTP requests and a reasonable percentage of SQL queries using prepared statements, several critical areas raise significant concerns. The plugin has a notable attack surface with 4 out of 5 entry points lacking proper authentication checks, including AJAX handlers and a shortcode. This is further exacerbated by a high percentage of improperly escaped output (61%), suggesting a substantial risk of Cross-Site Scripting (XSS) vulnerabilities.
The taint analysis reveals a flow with an unsanitized path and a high severity, indicating a potential for privilege escalation or sensitive data exposure. Coupled with the presence of the dangerous `create_function` function and only one nonce check across the entire plugin, the potential for attackers to exploit these weaknesses is amplified. The vulnerability history, showing a medium severity CVE that is currently unpatched and the common occurrence of CSRF vulnerabilities in the past, suggests a pattern of security oversights that require immediate attention.
Overall, the plugin's security posture is weak due to the combination of a large unprotected attack surface, inadequate output escaping, a critical taint flow, and a history of unpatched vulnerabilities. While the use of prepared statements and some capability checks are positive, they are overshadowed by the numerous and severe security weaknesses that put users at risk.
Key Concerns
- Unprotected AJAX handlers
- Unprotected shortcode
- High percentage of unescaped output
- Flow with unsanitized path (high severity)
- Dangerous function: create_function
- Only 1 nonce check
- Unpatched medium severity CVE
- High percentage of SQL queries without prepared statements
Slick Google Map Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Slick Google Map <= 0.3 - Cross-Site Request Forgery
Slick Google Map Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Slick Google Map Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 24
Maintenance & Trust
Slick Google Map Maintenance & Trust
Maintenance Signals
Community Trust
Slick Google Map Alternatives
Multiple Map Marker For Elementor Page Builder
map-multiple-marker
An Extended of Elementor Google Map Widget - Easily add multiple address pins onto the same map with support for different map types (Road Map/Satelli …
Snapycode Gmap
snapycode-gmap
SnapyCode Gmap This is a google map widget plugin for wordpress by snapycode.com This module has some option to configure the resultant map like- Z …
WP Go Maps (formerly WP Google Maps)
wp-google-maps
The easiest to use Google maps plugin! Create a custom Google map, map block, store locator or map widget with high quality markers containing categor …
iframe
iframe
[iframe src="http://www.youtube.com/embed/7_nAZQt9qu0" width="100%" height="500"] shortcode
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
Slick Google Map Developer Profile
1 plugin · 50 total installs
How We Detect Slick Google Map
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/slick-google-map/css/style.css/wp-content/plugins/slick-google-map/css/admin.css/wp-content/plugins/slick-google-map/js/jquery.google-map.min.js/wp-content/plugins/slick-google-map/js/slick-google-map.js/wp-content/plugins/slick-google-map/js/slick-google-map-admin.js/wp-content/plugins/slick-google-map/js/slick-google-map-admin-tinymce.js/wp-content/plugins/slick-google-map/assets/css/images/markers/1-default.png/wp-content/plugins/slick-google-map/js/jquery.google-map.min.js/wp-content/plugins/slick-google-map/js/slick-google-map.js/wp-content/plugins/slick-google-map/js/slick-google-map-admin.js/wp-content/plugins/slick-google-map/js/slick-google-map-admin-tinymce.js/wp-content/plugins/slick-google-map/css/style.css?ver=/wp-content/plugins/slick-google-map/css/admin.css?ver=/wp-content/plugins/slick-google-map/js/jquery.google-map.min.js?ver=/wp-content/plugins/slick-google-map/js/slick-google-map.js?ver=/wp-content/plugins/slick-google-map/js/slick-google-map-admin.js?ver=/wp-content/plugins/slick-google-map/js/slick-google-map-admin-tinymce.js?ver=HTML / DOM Fingerprints
slick-google-map-widgetsgmp-map-canvas<!-- Google Maps API Placeholder -->data-sgmp-map-idsgmp_google_map_varssgmp_global_map_language[google-map-v3