
SM Google Maps Security & Risk Analysis
wordpress.org/plugins/sm-google-mapsThe SM Google Maps is a wordpress widget plugin used to integrate google map to your web site widget area.
Is SM Google Maps Safe to Use in 2026?
Generally Safe
Score 85/100SM Google Maps has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The sm-google-maps plugin v1.0.0 exhibits a generally good security posture with no known vulnerabilities or recorded CVEs. The static analysis reveals a remarkably small attack surface, with no AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential for external exploitation. Furthermore, the code signals indicate a responsible approach to SQL queries, with 100% usage of prepared statements, and no dangerous functions, file operations, or external HTTP requests were detected. However, a significant concern arises from the output escaping, where only 28% of outputs are properly escaped. This indicates a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data or plugin-generated content is not adequately sanitized before being displayed to users.
The lack of detected taint flows and the absence of critical or high severity issues in code signals are positive indicators. The vulnerability history also suggests a clean track record for this plugin. Despite the absence of explicit security checks like nonces or capability checks (which is less concerning given the zero attack surface), the poor output escaping is the primary weakness. This suggests that while the plugin may not be easily exploitable through direct entry points, it could still be vulnerable to XSS attacks if specific, unhandled output scenarios exist within its functionality.
Key Concerns
- Low output escaping rate
SM Google Maps Security Vulnerabilities
SM Google Maps Code Analysis
Output Escaping
SM Google Maps Attack Surface
WordPress Hooks 1
Maintenance & Trust
SM Google Maps Maintenance & Trust
Maintenance Signals
Community Trust
SM Google Maps Alternatives
Maps Widget for Google Maps
google-maps-widget
Are your Google Maps slow? Try Map Widget for Google Maps. You'll have a fast Google Maps widget with a thumbnail & lightbox map in minutes!
Store Locator Widget
store-locator-widget
A fully featured store locator plugin that is incredibly quick and easy to configure, add locations and embed in your WordPress site.
Element Bits
element-bits
Element Bits adds a growing collection of lightweight, easy-to-use widgets to Elementor page builder, helping you build beautiful pages faster.
Simple Google Maps Widget
simple-google-maps-widget
A simple yet cool and intuitive Google maps widget for your website
WP Go Maps (formerly WP Google Maps)
wp-google-maps
The easiest to use Google maps plugin! Create a custom Google map, map block, store locator or map widget with high quality markers containing categor …
SM Google Maps Developer Profile
10 plugins · 650 total installs
How We Detect SM Google Maps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
https://maps.googleapis.com/maps/api/js?key=https://maps.googleapis.com/maps/api/js?key=&callback=initMapHTML / DOM Fingerprints
SMGoogleMaps_WidgetReplace the value of the key parameter with your own API key.id="map"name="apiKey"name="lat"name="lng"name="mapTypeId"id="map"+17 morevar map;