
Stellar Places Security & Risk Analysis
wordpress.org/plugins/stellar-placesEasily create, manage and display locations in a way that makes sense.
Is Stellar Places Safe to Use in 2026?
Generally Safe
Score 85/100Stellar Places has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The stellar-places plugin v1.3 demonstrates a generally strong security posture, with several good practices evident in its code. The absence of known CVEs, a complete lack of raw SQL queries, and a high percentage of properly escaped output are commendable. Furthermore, the presence of nonce and capability checks suggests an effort to protect against common WordPress exploits. However, the static analysis reveals a significant concern regarding taint analysis, specifically 5 flows with unsanitized paths categorized as high severity. This indicates potential vulnerabilities where external data might be improperly handled, leading to security risks if not adequately sanitized before use. The single file operation also warrants careful scrutiny, as it could be a vector for unauthorized file manipulation if not strictly controlled. Despite the lack of historical vulnerabilities, the high severity taint flows represent a tangible risk that needs immediate attention and remediation. The plugin's strengths in other areas are overshadowed by this critical finding in its data handling practices, suggesting a need for a thorough review of its input validation and sanitization mechanisms.
Key Concerns
- High severity taint flows with unsanitized paths
- File operation present
Stellar Places Security Vulnerabilities
Stellar Places Code Analysis
Output Escaping
Data Flow Analysis
Stellar Places Attack Surface
Shortcodes 1
WordPress Hooks 23
Maintenance & Trust
Stellar Places Maintenance & Trust
Maintenance Signals
Community Trust
Stellar Places Alternatives
Track Geolocation Of Users Using Contact Form 7
track-geolocation-of-users-using-contact-form-7
Track Geolocation Of Users Using Contact Form 7 allows you to get geolocation information with their form submission.
Simple Location
simple-location
Adds geographic location and weather support to WordPress.
Simple Fields Map extension
simple-fields-map-extension
Extension to Simple Fields that adds a field type for selecting a location on a Google Map.
Quick Maps
quick-maps
The easiest Google Maps integration for your Wordpress website [quick-maps]Orlando, Florida[/quick-maps] - No Google API required.
BuddyPress Maps
buddypress-maps
BuddyPress Maps is a component that allows to find and display location markers on a Google Map.
Stellar Places Developer Profile
8 plugins · 12K total installs
How We Detect Stellar Places
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/stellar-places/assets/css/frontend.css/wp-content/plugins/stellar-places/assets/js/frontend.js/wp-content/plugins/stellar-places/assets/js/frontend.jsstellar-places/assets/css/frontend.css?ver=stellar-places/assets/js/frontend.js?ver=HTML / DOM Fingerprints
stellar-places-map-canvasdata-stellar-places-map-auto-centerdata-stellar-places-map-auto-zoomdata-stellar-places-map-info-windowsdata-stellar-places-map-latdata-stellar-places-map-lngdata-stellar-places-map-locations+1 more