
Spotmap Security & Risk Analysis
wordpress.org/plugins/spotmapLive GPS tracking for WordPress — display positions from SPOT, Garmin inReach, OsmAnd, Teltonika, and more on interactive maps.
Is Spotmap Safe to Use in 2026?
Generally Safe
Score 100/100Spotmap has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "spotmap" plugin v0.11.2 exhibits a concerning security posture due to significant areas lacking proper authorization and sanitization. While the plugin has no recorded historical vulnerabilities, this does not negate the risks identified in the static analysis. The presence of unprotected AJAX handlers and flows with unsanitized paths are critical weaknesses that could lead to unauthorized actions or data manipulation. The low percentage of properly escaped output further exacerbates these risks, potentially exposing the application to cross-site scripting (XSS) vulnerabilities.
Despite the absence of dangerous functions and a reasonable effort in using prepared statements for SQL queries, the fundamental lack of security checks on entry points is a major concern. The vulnerability history of zero CVEs is positive, but it's important to note that this is a relatively new version and has not been subjected to extensive public scrutiny or exploitation. The plugin's strengths lie in its lack of bundled libraries and the absence of direct SQL injection vulnerabilities from raw queries. However, these are overshadowed by the identified security gaps.
In conclusion, "spotmap" v0.11.2 has several critical security concerns that need immediate attention. The unprotected entry points and unsanitized data flows present a clear attack surface. While the plugin's history is clean, this static analysis reveals potential for severe vulnerabilities. Developers should prioritize implementing robust authorization checks and thorough input sanitization to mitigate these risks.
Key Concerns
- Unprotected AJAX handlers
- Taint flow: Unsanitized path (Critical Severity)
- Taint flow: Unsanitized path (Critical Severity)
- Low percentage of properly escaped output
- No nonce checks on entry points
- No capability checks on entry points
Spotmap Security Vulnerabilities
Spotmap Release Timeline
Spotmap Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Spotmap Attack Surface
AJAX Handlers 2
Shortcodes 4
WordPress Hooks 12
Scheduled Events 5
Maintenance & Trust
Spotmap Maintenance & Trust
Maintenance Signals
Community Trust
Spotmap Alternatives
WP GPX Maps
wp-gpx-maps
Draws a GPX track with altitude graph. You can also display your nextgen gallery images in the map.
Trackserver
trackserver
GPS Track Server for TrackMe, OruxMaps and others
Images with GPS on GoogleMaps
images-with-gps-data-and-gpx-on-maps
Images with GPS on Google Maps displays your photos on a Google Maps map using GPS or without GPS Geotags.
GPXconnect
gpxconnect
Download GPX data to Garmin GPS devices.
OSM – OpenStreetMap
osm
Customize maps in your posts, pages, and widgets. GPX, KML, and more.
Spotmap Developer Profile
1 plugin · 40 total installs
How We Detect Spotmap
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/spotmap/includes/css/font-awesome-5.15-all.min.css/wp-content/plugins/spotmap/js/settings.jsHTML / DOM Fingerprints
data-spotmap-marker-icondata-spotmap-marker-shapedata-spotmap-marker-messagespotmap_settingsspotmap_markersspotmap_point_types[spotmap]