Snazzy Maps Security & Risk Analysis

wordpress.org/plugins/snazzy-maps

Apply styles to your Google Maps with the official Snazzy Maps WordPress plugin.

30K active installs v1.5.0 PHP + WP 3.0+ Updated May 7, 2025
googlegoogle-mapsmapsstyled-mapsstyles
92
A · Safe
CVEs total1
Unpatched0
Last CVEJul 24, 2018
Safety Verdict

Is Snazzy Maps Safe to Use in 2026?

Generally Safe

Score 92/100

Snazzy Maps has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Jul 24, 2018Updated 1yr ago
Risk Assessment

The snazzy-maps plugin version 1.5.0 exhibits a generally good security posture, primarily due to the absence of identified critical vulnerabilities in its static analysis. The plugin demonstrates strong adherence to secure coding practices by utilizing prepared statements for all SQL queries and maintaining a high percentage of properly escaped output. The presence of nonce checks further indicates an effort to mitigate common web vulnerabilities. However, there are areas for improvement. The taint analysis revealed two flows with unsanitized paths, which, although not classified as critical or high severity, represent potential avenues for exploitation if further input validation is not robustly implemented within the plugin's logic. While the plugin has a history of vulnerabilities, specifically Cross-Site Scripting, all past issues appear to be patched. The lack of any recent vulnerabilities (last one in 2018) is a positive sign. Overall, the plugin is relatively secure for this version, but the identified unsanitized paths warrant attention and careful monitoring.

Key Concerns

  • Flows with unsanitized paths
  • Past XSS vulnerability history
Vulnerabilities
1 published

Snazzy Maps Security Vulnerabilities

CVEs by Year

1 CVE in 2018
2018
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2018-17947medium · 6.1Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Snazzy Maps <= 1.1.4 - Multiple Cross-Site Scripting

Jul 24, 2018 Patched in 1.1.5 (2009d)
Version History

Snazzy Maps Release Timeline

v1.5.0Current
v1.4.0
v1.3.0
v1.2.1
v1.2.0
v1.1.5
v1.1.41 CVE
v1.1.31 CVE
v1.1.21 CVE
v1.1.11 CVE
v1.1.01 CVE
v1.0.61 CVE
v1.0.51 CVE
v1.0.41 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
v1.0.01 CVE
Code Analysis
Analyzed Mar 16, 2026

Snazzy Maps Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
52 escaped
Nonce Checks
6
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped57 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

6 flows2 with unsanitized paths
admin_add_custom_content (admin\index.php:66)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Snazzy Maps Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 5
actioninitsnazzymaps.php:104
actionwp_enqueue_scriptssnazzymaps.php:106
actionadmin_enqueue_scriptssnazzymaps.php:110
actionadmin_menusnazzymaps.php:112
actionadmin_head-appearance_page_snazzy_mapssnazzymaps.php:118
Maintenance & Trust

Snazzy Maps Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.6
Last updatedMay 7, 2025
PHP min version
Downloads535K

Community Trust

Rating84/100
Number of ratings15
Active installs30K
Developer Profile

Snazzy Maps Developer Profile

atmistinc

1 plugin · 30K total installs

73
trust score
Avg Security Score
92/100
Avg Patch Time
2009 days
View full developer profile
Detection Fingerprints

How We Detect Snazzy Maps

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/snazzy-maps/snazzymaps.js/wp-content/plugins/snazzy-maps/admin/index.js/wp-content/plugins/snazzy-maps/admin/index.css
Script Paths
snazzymaps.jsindex.js
Version Parameters
snazzymaps.js?ver=index.js?ver=index.css?ver=bower_components/history.js/scripts/bundled/html5/native.history.js?ver=bower_components/simple-query-string/src/simplequerystring.min.js?ver=bower_components/mustache/mustache.min.js?ver=

HTML / DOM Fingerprints

CSS Classes
sm-pluginsm-stylesm-mapsm-contentwelcome-panel
HTML Comments
Copyright 2014 Snazzy Maps (email : support@snazzymaps.com)This program is free software; you can redistribute it and/or modifyThis program is distributed in the hope that it will be useful,You should have received a copy of the GNU General Public License+8 more
Data Attributes
id="style-template"type="text/template"name="new_style"id="welcome-panel"class="wrap sm-plugin"class="col-sm-6 col-md-4 style"+10 more
JS Globals
SnazzyDataForSnazzyMapsSnazzyData
FAQ

Frequently Asked Questions about Snazzy Maps