Store Locator with Google Map Security & Risk Analysis

wordpress.org/plugins/store-locator-with-google-map

Now your customers can find your location easily with our simple, free Google Maps one store locator. Customizable and Responsive.

20 active installs v1.2.0 PHP 7.0+ WP 3.0.1+ Updated Apr 14, 2025
google-mapstore-google-mapstore-locatorstore-mapzotabox
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Store Locator with Google Map Safe to Use in 2026?

Generally Safe

Score 100/100

Store Locator with Google Map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "store-locator-with-google-map" plugin version 1.2.0 exhibits a generally good security posture based on the static analysis provided. The absence of known CVEs and a clean vulnerability history is a strong positive indicator, suggesting the developers have historically prioritized security or have not encountered significant issues. The attack surface is small, consisting of only two AJAX handlers, and importantly, none are found to be unprotected by authentication checks, which is excellent practice.

However, there are areas for improvement. While the plugin uses prepared statements for all SQL queries and has nonce checks in place, there are concerns regarding output escaping. With 6 total outputs and 33% being improperly escaped, this represents a potential vector for Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is reflected directly in the output without proper sanitization. The taint analysis did not reveal any critical or high-severity issues, which is reassuring, but the unescaped output remains a notable weakness.

In conclusion, the plugin has several strengths, including a limited attack surface, secure SQL handling, and the presence of nonce checks. The lack of historical vulnerabilities further bolsters confidence. The primary concern stems from the percentage of unescaped output, which, while not flagged as critical in taint analysis, could still pose a security risk. Addressing the unescaped output would significantly enhance the plugin's overall security.

Key Concerns

  • Unescaped output detected (33%)
Vulnerabilities
None known

Store Locator with Google Map Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Store Locator with Google Map Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
4 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

67% escaped6 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
update_zb_sl_code (store-locator-with-google-map.php:181)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Store Locator with Google Map Attack Surface

Entry Points2
Unprotected0

AJAX Handlers 2

authwp_ajax_update_zb_sl_codestore-locator-with-google-map.php:178
noprivwp_ajax_update_zb_sl_codestore-locator-with-google-map.php:179
WordPress Hooks 4
actionadmin_initstore-locator-with-google-map.php:15
actionadmin_noticesstore-locator-with-google-map.php:46
actionadmin_menustore-locator-with-google-map.php:82
actionwp_headstore-locator-with-google-map.php:175
Maintenance & Trust

Store Locator with Google Map Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedApr 14, 2025
PHP min version7.0
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs20
Developer Profile

Store Locator with Google Map Developer Profile

Zotabox

12 plugins · 4K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
1712 days
View full developer profile
Detection Fingerprints

How We Detect Store Locator with Google Map

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/store-locator-with-google-map/assets/images/logo-zotabox.png/wp-content/plugins/store-locator-with-google-map/assets/js/main.js
Script Paths
/wp-content/plugins/store-locator-with-google-map/assets/js/main.js
Version Parameters
store-locator-with-google-map/assets/js/main.js?v=

HTML / DOM Fingerprints

CSS Classes
ztb-register-formztb-submit-buttonztb-wrapperztb-logoztb-code-wrapperztb-titleaccount-inputztb-button
Data Attributes
zb-plugin
JS Globals
ZBT_WP_ADMIN_URLZTB_BASE_URL
FAQ

Frequently Asked Questions about Store Locator with Google Map