
StoreRocket Store Locator Security & Risk Analysis
wordpress.org/plugins/storerocket-store-locatorAdd the first-in-class modern StoreRocket Store Locator to your WordPress website.
Is StoreRocket Store Locator Safe to Use in 2026?
Generally Safe
Score 85/100StoreRocket Store Locator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
Based on the static analysis and vulnerability history, the storerocket-store-locator plugin v1.0.0 appears to have a strong security posture. The plugin has a very limited attack surface with no exposed AJAX handlers, REST API routes, shortcodes, or cron events. This significantly reduces the potential for attackers to interact with the plugin directly. Furthermore, the code analysis shows good security practices, with all SQL queries using prepared statements and a high percentage of output being properly escaped. The absence of dangerous functions, file operations, and external HTTP requests further strengthens its security. The plugin also enforces capability checks, indicating an awareness of access control. The lack of any known CVEs, past or present, suggests a history of secure development or timely patching, which is a positive indicator. The taint analysis also revealed no critical or high severity issues, further reinforcing the secure nature of the code. The plugin's strengths lie in its minimal attack surface and diligent use of secure coding practices like prepared statements and output escaping. However, a notable weakness is the complete absence of nonce checks, which, while not directly exploitable given the other zero entry points, represents a missed opportunity for defense-in-depth. Without any entry points, this lack of nonce checks doesn't pose an immediate threat but highlights an area where future development could improve.
Key Concerns
- Missing nonce checks
StoreRocket Store Locator Security Vulnerabilities
StoreRocket Store Locator Release Timeline
StoreRocket Store Locator Code Analysis
Output Escaping
StoreRocket Store Locator Attack Surface
WordPress Hooks 18
Maintenance & Trust
StoreRocket Store Locator Maintenance & Trust
Maintenance Signals
Community Trust
StoreRocket Store Locator Alternatives
StoreRocket Store Locator Developer Profile
1 plugin · 30 total installs
How We Detect StoreRocket Store Locator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/storerocket-store-locator/assets/css/plugin.css/wp-content/plugins/storerocket-store-locator/assets/css/editor.css/wp-content/plugins/storerocket-store-locator/assets/js/editor.js/wp-content/plugins/storerocket-store-locator/assets/js/editor.jsstorerocket-store-locator/assets/css/plugin.css?ver=storerocket-store-locator/assets/css/editor.css?ver=storerocket-store-locator/assets/js/editor.js?ver=HTML / DOM Fingerprints
wp-block-wp-storerocket-storerocket-block[storerocket_locator]