
Slick Google Map Security & Risk Analysis
wordpress.org/plugins/slick-google-mapEmbed Google Maps (with your own API key) or OpenStreetMap/Leaflet maps via shortcode or Gutenberg block.
Is Slick Google Map Safe to Use in 2026?
Generally Safe
Score 99/100Slick Google Map has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "slick-google-map" v0.3 plugin presents a moderate security risk. While it shows some positive signs like a relatively low number of external HTTP requests and a reasonable percentage of SQL queries using prepared statements, several critical areas raise significant concerns. The plugin has a notable attack surface with 4 out of 5 entry points lacking proper authentication checks, including AJAX handlers and a shortcode. This is further exacerbated by a high percentage of improperly escaped output (61%), suggesting a substantial risk of Cross-Site Scripting (XSS) vulnerabilities.
The taint analysis reveals a flow with an unsanitized path and a high severity, indicating a potential for privilege escalation or sensitive data exposure. Coupled with the presence of the dangerous `create_function` function and only one nonce check across the entire plugin, the potential for attackers to exploit these weaknesses is amplified. The vulnerability history, showing a medium severity CVE that is currently unpatched and the common occurrence of CSRF vulnerabilities in the past, suggests a pattern of security oversights that require immediate attention.
Overall, the plugin's security posture is weak due to the combination of a large unprotected attack surface, inadequate output escaping, a critical taint flow, and a history of unpatched vulnerabilities. While the use of prepared statements and some capability checks are positive, they are overshadowed by the numerous and severe security weaknesses that put users at risk.
Key Concerns
- Unprotected AJAX handlers
- Unprotected shortcode
- High percentage of unescaped output
- Flow with unsanitized path (high severity)
- Dangerous function: create_function
- Only 1 nonce check
- Unpatched medium severity CVE
- High percentage of SQL queries without prepared statements
Slick Google Map Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Slick Google Map <= 0.3 - Cross-Site Request Forgery
Slick Google Map Release Timeline
Slick Google Map Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Slick Google Map Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 24
Maintenance & Trust
Slick Google Map Maintenance & Trust
Maintenance Signals
Community Trust
Slick Google Map Alternatives
MapPress – Google Maps, OpenStreetMap & Leaflet
mappress-google-maps-for-wordpress
Add unlimited Google Maps, Leaflet & OpenStreetMap to WordPress. Create a map, map block or store locator — no API key needed for free maps.
Out of the Block: OpenStreetMap
ootb-openstreetmap
A map block for Gutenberg using OpenStreetMap and Leaflet that needs no API keys and works out of the box. Or should we say, ...Out of the Block?
Easy Map- Store Locator Plugin for WordPress (No API Key Required)
easy-map
Create store locator maps, multiple markers, drawings, and interactive WordPress maps with OpenStreetMap, Google Maps, Bing Maps, and Leaflet.
Simple Map Locator
simple-map-locator
Interactive maps and markers on your posts and pages with simple shortcodes.
CartoBlocks for Leaflet
cartoblocks-for-leaflet
A Gutenberg block that gives you a full visual editor for all Leaflet Map plugin shortcodes — no shortcode writing required.
Slick Google Map Developer Profile
1 plugin · 50 total installs
How We Detect Slick Google Map
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/slick-google-map/css/style.css/wp-content/plugins/slick-google-map/css/admin.css/wp-content/plugins/slick-google-map/js/jquery.google-map.min.js/wp-content/plugins/slick-google-map/js/slick-google-map.js/wp-content/plugins/slick-google-map/js/slick-google-map-admin.js/wp-content/plugins/slick-google-map/js/slick-google-map-admin-tinymce.js/wp-content/plugins/slick-google-map/assets/css/images/markers/1-default.png/wp-content/plugins/slick-google-map/js/jquery.google-map.min.js/wp-content/plugins/slick-google-map/js/slick-google-map.js/wp-content/plugins/slick-google-map/js/slick-google-map-admin.js/wp-content/plugins/slick-google-map/js/slick-google-map-admin-tinymce.js/wp-content/plugins/slick-google-map/css/style.css?ver=/wp-content/plugins/slick-google-map/css/admin.css?ver=/wp-content/plugins/slick-google-map/js/jquery.google-map.min.js?ver=/wp-content/plugins/slick-google-map/js/slick-google-map.js?ver=/wp-content/plugins/slick-google-map/js/slick-google-map-admin.js?ver=/wp-content/plugins/slick-google-map/js/slick-google-map-admin-tinymce.js?ver=HTML / DOM Fingerprints
slick-google-map-widgetsgmp-map-canvas<!-- Google Maps API Placeholder -->data-sgmp-map-idsgmp_google_map_varssgmp_global_map_language[google-map-v3