Store Locator for WordPress📍 Security & Risk Analysis

wordpress.org/plugins/storelocator

Create a store locator for your website in minutes. Add all the store locations in google sheets and embed map on your website.

1K active installs v1.2.0 PHP + WP 4.5.0+ Updated Nov 28, 2025
business-locationsgoogle-mapsmapsstore-finderstore-locator
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Store Locator for WordPress📍 Safe to Use in 2026?

Generally Safe

Score 100/100

Store Locator for WordPress📍 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "storelocator" plugin v1.2.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by not utilizing dangerous functions, performing all SQL queries with prepared statements, and avoiding file operations. The presence of a nonce check is also a positive indicator. However, there are notable areas of concern. The plugin has a small attack surface with three entry points, but one of these, an AJAX handler, lacks authentication checks. This is a significant vulnerability that could allow unauthorized users to trigger functionality without proper authorization. Additionally, while the majority of output is properly escaped, a substantial percentage is not, potentially leading to cross-site scripting (XSS) vulnerabilities if user-supplied data is involved. The plugin's vulnerability history is clean, with no recorded CVEs, which suggests a history of secure development or a lack of past scrutiny. Despite this clean history, the identified security weaknesses in the code analysis, particularly the unprotected AJAX handler, warrant caution.

Key Concerns

  • AJAX handler without authentication check
  • Significant portion of output not properly escaped
Vulnerabilities
None known

Store Locator for WordPress📍 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Store Locator for WordPress📍 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
36 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

73% escaped49 total outputs
Attack Surface
1 unprotected

Store Locator for WordPress📍 Attack Surface

Entry Points3
Unprotected1

AJAX Handlers 2

authwp_ajax_resetstorelocator.php:283
authwp_ajax_storelocator_submit_uninstall_reason_actionstorelocator.php:343

Shortcodes 1

[storelocator] storelocator.php:124
WordPress Hooks 7
actionactivated_pluginstorelocator.php:60
actionadmin_noticesstorelocator.php:90
actionadmin_initstorelocator.php:102
actionadmin_menustorelocator.php:183
actionadmin_initstorelocator.php:248
actionadmin_enqueue_scriptsstorelocator.php:294
actionshutdownstorelocator.php:353
Maintenance & Trust

Store Locator for WordPress📍 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 28, 2025
PHP min version
Downloads17K

Community Trust

Rating100/100
Number of ratings5
Active installs1K
Developer Profile

Store Locator for WordPress📍 Developer Profile

Micro.company

2 plugins · 3K total installs

92
trust score
Avg Security Score
88/100
Avg Patch Time
7 days
View full developer profile
Detection Fingerprints

How We Detect Store Locator for WordPress📍

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/storelocator/storelocator-logo.png/wp-content/plugins/storelocator/css/storelocator.css/wp-content/plugins/storelocator/js/storelocator.js
Script Paths
/wp-content/plugins/storelocator/js/storelocator.js

HTML / DOM Fingerprints

CSS Classes
storelocator-logo
Data Attributes
data-plugin-name="storelocator"
JS Globals
storelocator
Shortcode Output
<iframe src="https://locatestore.com/allow="geolocation"frameBorder="0"style="width:100% !important;max-width:100% !important;margin:10px;"
FAQ

Frequently Asked Questions about Store Locator for WordPress📍