
Storepoint Store Locator Security & Risk Analysis
wordpress.org/plugins/storepoint-store-locatorAdd a store locator map, dealer locator, or location finder to any WordPress page. Powered by Storepoint.
Is Storepoint Store Locator Safe to Use in 2026?
Generally Safe
Score 100/100Storepoint Store Locator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The storepoint-store-locator plugin v1.0.1 exhibits a generally strong security posture based on the provided static analysis. The absence of dangerous functions, external HTTP requests, file operations, and a high percentage of properly escaped output are positive indicators. The fact that all SQL queries use prepared statements further strengthens this assessment, mitigating risks of SQL injection. The plugin also benefits from a lack of known vulnerabilities and a clean history, suggesting a commitment to security by its developers.
However, there are areas that warrant attention. The presence of a shortcode as an entry point, while not inherently insecure, represents a potential attack vector if not handled with utmost care. Critically, the analysis indicates a complete absence of nonce checks and capability checks. This is a significant concern, as it means that any action triggered by the shortcode or potentially other (unseen) entry points could be executed by any user, regardless of their permissions or authenticated status. This lack of authorization checks presents a notable risk.
In conclusion, while the plugin demonstrates good development practices in areas like output escaping and SQL querying, the complete omission of nonce and capability checks introduces a substantial security weakness. The attack surface is minimal, but the lack of authorization on the existing shortcode entry point is a critical oversight that could lead to unauthorized actions. The plugin's clean vulnerability history is encouraging, but this lack of fundamental security checks means it's susceptible to vulnerabilities that haven't manifested in past versions.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Shortcode entry point without checks
Storepoint Store Locator Security Vulnerabilities
Storepoint Store Locator Release Timeline
Storepoint Store Locator Code Analysis
Output Escaping
Storepoint Store Locator Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
Storepoint Store Locator Maintenance & Trust
Maintenance Signals
Community Trust
Storepoint Store Locator Alternatives
Store Locator WordPress
agile-store-locator
Agile Store Locator is a premium store finder plugin designed to offer you immediate access to all the best stores in your local area.
WP Store Locator
wp-store-locator
An easy to use location management system that enables users to search for nearby physical stores.
Locatoraid Store Locator
locatoraid
A lightweight, reliable store locator backed by ongoing maintenance, updates, and support. Premium version adds CSV import, custom fields, custom map …
Store Locator for WordPress📍
storelocator
Create a store locator for your website in minutes. Add all the store locations in google sheets and embed map on your website.
Custom WP Store Locator
custom-store-locator
Create and manage multiple locations on Map. you can use a search widget, store locator map, category filter, and near location finder features.
Storepoint Store Locator Developer Profile
1 plugin · 0 total installs
How We Detect Storepoint Store Locator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/storepoint-store-locator/assets/css/style.csshttps://widget.storepoint.co/embed.jsstorepoint-store-locator/assets/css/style.css?ver=https://widget.storepoint.co/embed.js?ver=HTML / DOM Fingerprints
storepoint-filter-dropdownstorepoint-filter-inlinestorepoint-filter-open-nowstorepoint-custom-filterdata-map-idwindow.storepointBlockDataStorepointWidget<div id="storepoint-<style>#