Storemapper Store Locator Map Security & Risk Analysis

wordpress.org/plugins/storemapper

The Store Locator App: Easy to install, fully customizable and proven to drive more traffic

80 active installs v2.0.3.7 PHP 5.4.45+ WP 4.4+ Updated May 22, 2025
storemapperdealer-locatorgoogle-mapstore-locationstore-locator
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Storemapper Store Locator Map Safe to Use in 2026?

Generally Safe

Score 100/100

Storemapper Store Locator Map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10mo ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "storemapper" plugin v2.0.3.7 exhibits a generally strong security posture. The absence of any registered CVEs, including critical or high-severity ones, is a significant positive indicator of its historical security. Furthermore, the code analysis reveals no dangerous functions, no raw SQL queries, and a very high percentage of properly escaped output, all of which are excellent security practices.

However, the analysis does highlight some areas of concern. The plugin has zero recorded nonce checks, and while there are capability checks present, their effectiveness is not guaranteed without proper implementation. The lack of taint analysis data suggests that either the analysis tool did not identify any potential taint flows, or the plugin has design elements that prevent such flows from being readily detected by typical static analysis tools. Without any entry points like AJAX handlers, REST API routes, or shortcodes, the direct attack surface appears minimal, but this also means that any potential vulnerabilities in the existing code would be harder to discover and exploit through these common vectors.

In conclusion, the plugin demonstrates a commitment to secure coding principles, particularly in handling SQL and output. The absence of known vulnerabilities is reassuring. The main weaknesses lie in the complete lack of nonce checks and the limited visibility into potential taint flows, which could represent an undiscovered risk. While the current attack surface is small, the absence of common security checks could be a point of failure if new entry points were to be introduced or if existing code has subtle flaws.

Key Concerns

  • No nonce checks found
  • No taint analysis data
Vulnerabilities
None known

Storemapper Store Locator Map Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Storemapper Store Locator Map Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
2
39 escaped
Nonce Checks
0
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

95% escaped41 total outputs
Attack Surface

Storemapper Store Locator Map Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
filtermce_external_pluginsincludes\editor.class.php:26
filtermce_buttonsincludes\editor.class.php:27
actionadmin_headincludes\editor.class.php:28
actioninitincludes\init.class.php:21
actioninitincludes\init.class.php:22
actionadmin_enqueue_scriptsincludes\init.class.php:23
actionadmin_menuincludes\init.class.php:24
actionwidgets_initincludes\init.class.php:26
actionadmin_initincludes\settings.class.php:18
actionafter_setup_themewp-storemapper.php:59
actionadmin_noticeswp-storemapper.php:60
Maintenance & Trust

Storemapper Store Locator Map Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 22, 2025
PHP min version5.4.45
Downloads5K

Community Trust

Rating100/100
Number of ratings1
Active installs80
Developer Profile

Storemapper Store Locator Map Developer Profile

storemapper

1 plugin · 80 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Storemapper Store Locator Map

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/storemapper/assets/css/admin.min.css
Script Paths
https://storemapper.co/js/widget.min.js

HTML / DOM Fingerprints

Data Attributes
data-storemapper-startdata-storemapper-id
Shortcode Output
<div id='storemapper'>
FAQ

Frequently Asked Questions about Storemapper Store Locator Map