
TraveledMap Trip itinerary: Embedded map Security & Risk Analysis
wordpress.org/plugins/traveledmap-trip-itinerary-embedded-mapCreate interactive blog posts thanks to a map moving along your trip's steps while user reads. The map can be customized to fit your theme.
Is TraveledMap Trip itinerary: Embedded map Safe to Use in 2026?
Generally Safe
Score 92/100TraveledMap Trip itinerary: Embedded map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "traveledmap-trip-itinerary-embedded-map" plugin version 1.2.1 exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, external HTTP requests, and a lack of known vulnerabilities in its history are strong indicators of good development practices. The plugin also demonstrates a commendable approach to output escaping, with a high percentage of outputs being properly sanitized, significantly reducing the risk of cross-site scripting (XSS) vulnerabilities.
However, there are some areas for improvement. The static analysis reveals the presence of four shortcodes which serve as entry points into the plugin's functionality. While the analysis indicates these entry points are not explicitly unprotected (0 unprotected entry points), the lack of explicit capability checks and nonce checks on these shortcodes is a significant concern. This absence means that any authenticated user, regardless of their role or permissions, could potentially trigger the functionality associated with these shortcodes. This could lead to unintended actions or information disclosure if the shortcode's functionality is not inherently secure.
In conclusion, the plugin benefits from clean code practices regarding sensitive operations like SQL and output handling, and its vulnerability history is clean. The primary weakness lies in the potential for privilege escalation or unauthorized actions through shortcodes due to the absence of robust access control mechanisms like capability checks. Addressing this would significantly enhance its overall security.
Key Concerns
- Missing capability checks on shortcodes
- Missing nonce checks on shortcodes
- Less than 100% properly escaped output
TraveledMap Trip itinerary: Embedded map Security Vulnerabilities
TraveledMap Trip itinerary: Embedded map Code Analysis
Output Escaping
TraveledMap Trip itinerary: Embedded map Attack Surface
Shortcodes 4
WordPress Hooks 16
Maintenance & Trust
TraveledMap Trip itinerary: Embedded map Maintenance & Trust
Maintenance Signals
Community Trust
TraveledMap Trip itinerary: Embedded map Alternatives
Nomad World Map
nomad-world-map
Create your own custom travel map. Link locations on the map to blog posts and share your travel plans.
Travelmap
travelmap
Generates a map of your travels in any post or page based on a list of places.
WP Trip Summary
wp-trip-summary
A WordPress trip summary plugin to help travel bloggers manage and display structured information about their train rides and biking or hiking trips.
MapGeo – Interactive Geo Maps
interactive-geo-maps
Create interactive vector maps of the world, continents, any country in the world and specific regions, including individual US state county maps.
Booking.com Product Helper
bookingcom-product-helper
The Booking.com Product Helper allows you to embed any Booking.com affiliate product anywhere on your website.
TraveledMap Trip itinerary: Embedded map Developer Profile
1 plugin · 80 total installs
How We Detect TraveledMap Trip itinerary: Embedded map
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/traveledmap-trip-itinerary-embedded-map/src/metabox/style.csshttps://cdn.jsdelivr.net/gh/traveledmap/trip-embedder-js@$version/dist/traveledmap-trip.min.jsplugins/traveledmap-trip-itinerary-embedded-map/src/metabox/style.css?ver=plugins/traveledmap-trip-itinerary-embedded-map/src/trip-block/buildplugins/traveledmap-trip-itinerary-embedded-map/src/trip-step-block/buildHTML / DOM Fingerprints
traveledmap-stretchable-mapdata-traveledmap-user-iddata-traveledmap-trip-iddata-map-heightdata-standard-map-heightdata-extended-map-heightdata-should-show-pictures+8 moretraveledmap_user_idtraveledmap_trip_idSDK_VERSIONTraveledMap_Utils[traveledmap_map]