
TCBD Google Map Security & Risk Analysis
wordpress.org/plugins/tcbd-google-mapThis plugin will enable Awesome Google map in your Wordpress theme.
Is TCBD Google Map Safe to Use in 2026?
Generally Safe
Score 92/100TCBD Google Map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'tcbd-google-map' plugin version 2.1 exhibits a generally good security posture based on the provided static analysis. The absence of known vulnerabilities, critical taint flows, and dangerous functions is a significant strength. Furthermore, all SQL queries are prepared, and there are no file operations or external HTTP requests, reducing potential attack vectors. The presence of capability checks on certain entry points also indicates an awareness of authorization mechanisms.
However, there are areas for improvement. The static analysis revealed that only 67% of output escaping is properly implemented, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not sanitized before being displayed. The absence of nonce checks on the single identified shortcode entry point is also a concern, as it might allow for Cross-Site Request Forgery (CSRF) attacks, especially if the shortcode performs any state-changing actions.
With no recorded vulnerabilities historically, this plugin appears to be well-maintained or has not been a target. Nevertheless, the identified output escaping and nonce check deficiencies present potential risks. While the attack surface is small and largely protected by capability checks, these specific coding practices could still be exploited. Therefore, while the plugin is in a relatively secure state, addressing the output escaping and nonce check issues would significantly enhance its overall security.
Key Concerns
- Insufficient output escaping
- Missing nonce check on shortcode
TCBD Google Map Security Vulnerabilities
TCBD Google Map Release Timeline
TCBD Google Map Code Analysis
Bundled Libraries
Output Escaping
TCBD Google Map Attack Surface
Shortcodes 1
WordPress Hooks 9
Maintenance & Trust
TCBD Google Map Maintenance & Trust
Maintenance Signals
Community Trust
TCBD Google Map Alternatives
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
WP Store Locator
wp-store-locator
An easy to use location management system that enables users to search for nearby physical stores.
MapPress Maps for WordPress
mappress-google-maps-for-wordpress
MapPress is the easiest way to add unlimited interactive Google and Leaflet maps to WordPress.
Store Locator WordPress
agile-store-locator
Agile Store Locator is a premium store finder plugin designed to offer you immediate access to all the best stores in your local area.
Maps Plugin using Google Maps for WordPress – WP Google Map
gmap-embed
Google Map plugin for WordPress is very Simple, light-weight and Easy to use Google Custom Map with markers in Posts, Pages, Sidebar as shortcode.
TCBD Google Map Developer Profile
24 plugins · 1K total installs
How We Detect TCBD Google Map
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/tcbd-google-map/js/tinymce.js/wp-content/plugins/tcbd-google-map/js/tcbd-maplace-0.1.3.min.js/wp-content/plugins/tcbd-google-map/css/tcbd-map-css.css//maps.google.com/maps/api/js?sensor=false&libraries=geometry&v=3.7&key=/wp-content/plugins/tcbd-google-map/js/tcbd-maplace-0.1.3.min.js?ver=0.1.3HTML / DOM Fingerprints
id="gmap"id="controls"Maplace<div style="height: ; width: ;" id="gmap"></div><div id="controls"></div>