
Storemapper Store Locator Map Security & Risk Analysis
wordpress.org/plugins/storemapperThe Store Locator App: Easy to install, fully customizable and proven to drive more traffic
Is Storemapper Store Locator Map Safe to Use in 2026?
Generally Safe
Score 100/100Storemapper Store Locator Map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the provided static analysis and vulnerability history, the "storemapper" plugin v2.0.3.7 exhibits a generally strong security posture. The absence of any registered CVEs, including critical or high-severity ones, is a significant positive indicator of its historical security. Furthermore, the code analysis reveals no dangerous functions, no raw SQL queries, and a very high percentage of properly escaped output, all of which are excellent security practices.
However, the analysis does highlight some areas of concern. The plugin has zero recorded nonce checks, and while there are capability checks present, their effectiveness is not guaranteed without proper implementation. The lack of taint analysis data suggests that either the analysis tool did not identify any potential taint flows, or the plugin has design elements that prevent such flows from being readily detected by typical static analysis tools. Without any entry points like AJAX handlers, REST API routes, or shortcodes, the direct attack surface appears minimal, but this also means that any potential vulnerabilities in the existing code would be harder to discover and exploit through these common vectors.
In conclusion, the plugin demonstrates a commitment to secure coding principles, particularly in handling SQL and output. The absence of known vulnerabilities is reassuring. The main weaknesses lie in the complete lack of nonce checks and the limited visibility into potential taint flows, which could represent an undiscovered risk. While the current attack surface is small, the absence of common security checks could be a point of failure if new entry points were to be introduced or if existing code has subtle flaws.
Key Concerns
- No nonce checks found
- No taint analysis data
Storemapper Store Locator Map Security Vulnerabilities
Storemapper Store Locator Map Code Analysis
Output Escaping
Storemapper Store Locator Map Attack Surface
WordPress Hooks 11
Maintenance & Trust
Storemapper Store Locator Map Maintenance & Trust
Maintenance Signals
Community Trust
Storemapper Store Locator Map Alternatives
Progus Store Locator Map (No API Key Required)
progus-store-locator
Powerful Store, Dealer & Stockist Locator with all features for just $3.99/month. Trusted by 4,000+ businesses worldwide.
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
WP Store Locator
wp-store-locator
An easy to use location management system that enables users to search for nearby physical stores.
MapPress Maps for WordPress
mappress-google-maps-for-wordpress
MapPress is the easiest way to add unlimited interactive Google and Leaflet maps to WordPress.
Store Locator WordPress
agile-store-locator
Agile Store Locator is a premium store finder plugin designed to offer you immediate access to all the best stores in your local area.
Storemapper Store Locator Map Developer Profile
1 plugin · 80 total installs
How We Detect Storemapper Store Locator Map
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/storemapper/assets/css/admin.min.csshttps://storemapper.co/js/widget.min.jsHTML / DOM Fingerprints
data-storemapper-startdata-storemapper-id<div id='storemapper'>