
Events Manager – OpenStreetMaps Security & Risk Analysis
wordpress.org/plugins/stonehenge-em-osmOpenStreetMaps for Events Manager. An add-on to replace Google Maps with OpenStreetMap. 0% Google, 100% open source.
Is Events Manager – OpenStreetMaps Safe to Use in 2026?
Use With Caution
Score 63/100Events Manager – OpenStreetMaps has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'stonehenge-em-osm' plugin v4.2.1 presents a moderate security risk. While it demonstrates some positive security practices, such as a relatively low number of file operations and external HTTP requests, and a decent percentage of SQL queries using prepared statements and output escaping, significant concerns remain. The most alarming finding is the large attack surface with 17 AJAX handlers, 16 of which lack authentication checks. This is a major gateway for potential unauthorized actions. Furthermore, the presence of one unsanitized path in the taint analysis, even without critical or high severity, indicates a potential for vulnerability that needs investigation. The plugin's vulnerability history, including a known medium-severity CVE that is currently unpatched and related to Cross-Site Scripting, reinforces the need for caution. This suggests a pattern of past security flaws that have not been fully addressed, increasing the likelihood of future exploitable issues. Overall, the plugin has some strengths but is significantly weakened by its numerous unprotected entry points and a history of unpatched vulnerabilities.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized path in taint analysis
- Unpatched CVE (medium severity)
- Missing nonce checks on AJAX
- Less than 100% prepared SQL statements
- Less than 100% properly escaped output
Events Manager – OpenStreetMaps Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Events Manager – OpenStreetMaps <= 4.2.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
Events Manager – OpenStreetMaps Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Events Manager – OpenStreetMaps Attack Surface
AJAX Handlers 17
Shortcodes 4
WordPress Hooks 52
Maintenance & Trust
Events Manager – OpenStreetMaps Maintenance & Trust
Maintenance Signals
Community Trust
Events Manager – OpenStreetMaps Alternatives
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
Leaflet Maps Marker (Google Maps, OpenStreetMap, Bing Maps)
leaflet-maps-marker
The most comprehensive & user-friendly mapping solution for WordPress
Out of the Block: OpenStreetMap
ootb-openstreetmap
A map block for Gutenberg using OpenStreetMap and Leaflet that needs no API keys and works out of the box. Or should we say, ...Out of the Block?
Events Manager OpenStreetMap
events-manager-openstreetmap
Events Manager OpenStreetMap is a WordPress plugin for Events Manager. It allows you to replace Google Maps to OpenStreetMap on all your event locatio …
MatrixMaps – Interactive Maps, Map Blocks
geo-maps
Create beautiful, interactive maps for your WordPress website with MatrixMaps. The perfect solution for adding Google Maps and OpenStreetMap with unli …
Events Manager – OpenStreetMaps Developer Profile
9 plugins · 1K total installs
How We Detect Events Manager – OpenStreetMaps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/stonehenge-em-osm/assets/example-custom-markers.png/wp-content/plugins/stonehenge-em-osm/classes/class-functions.php/wp-content/plugins/stonehenge-em-osm/classes/class-admin.php/wp-content/plugins/stonehenge-em-osm/classes/class-metabox.php/wp-content/plugins/stonehenge-em-osm/classes/class-customize.php/wp-content/plugins/stonehenge-em-osm/classes/class-maps.php/wp-content/plugins/stonehenge-em-osm/classes/class-init.php+1 morestonehenge-em-osm/style.css?ver=stonehenge-em-osm/script.js?ver=HTML / DOM Fingerprints
em-osm-map-containercustom-marker-iconem-osm-custom-markerem-osm-custom-icon<!-- Stonehenge EM OSM - Init --><!-- Stonehenge EM OSM - Map Container -->data-em-osm-marker-shapedata-em-osm-marker-colordata-em-osm-marker-icondata-em-osm-marker-iconcolordata-em-osm-location-idstonehenge_em_osm_optionsstonehenge_em_osm_markersstonehenge_em_osm_map_settings<div class="em-osm-map-container"<div id="em-osm-map-<div class="em-osm-custom-marker"