TraveledMap Trip itinerary: Embedded map Security & Risk Analysis

wordpress.org/plugins/traveledmap-trip-itinerary-embedded-map

Create interactive blog posts thanks to a map moving along your trip's steps while user reads. The map can be customized to fit your theme.

80 active installs v1.2.1 PHP 5.6+ WP 3.0.1+ Updated Dec 18, 2024
mappicturestraveltraveledmaptrip
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is TraveledMap Trip itinerary: Embedded map Safe to Use in 2026?

Generally Safe

Score 92/100

TraveledMap Trip itinerary: Embedded map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "traveledmap-trip-itinerary-embedded-map" plugin version 1.2.1 exhibits a generally positive security posture based on the provided static analysis. The absence of dangerous functions, raw SQL queries, file operations, external HTTP requests, and a lack of known vulnerabilities in its history are strong indicators of good development practices. The plugin also demonstrates a commendable approach to output escaping, with a high percentage of outputs being properly sanitized, significantly reducing the risk of cross-site scripting (XSS) vulnerabilities.

However, there are some areas for improvement. The static analysis reveals the presence of four shortcodes which serve as entry points into the plugin's functionality. While the analysis indicates these entry points are not explicitly unprotected (0 unprotected entry points), the lack of explicit capability checks and nonce checks on these shortcodes is a significant concern. This absence means that any authenticated user, regardless of their role or permissions, could potentially trigger the functionality associated with these shortcodes. This could lead to unintended actions or information disclosure if the shortcode's functionality is not inherently secure.

In conclusion, the plugin benefits from clean code practices regarding sensitive operations like SQL and output handling, and its vulnerability history is clean. The primary weakness lies in the potential for privilege escalation or unauthorized actions through shortcodes due to the absence of robust access control mechanisms like capability checks. Addressing this would significantly enhance its overall security.

Key Concerns

  • Missing capability checks on shortcodes
  • Missing nonce checks on shortcodes
  • Less than 100% properly escaped output
Vulnerabilities
None known

TraveledMap Trip itinerary: Embedded map Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

TraveledMap Trip itinerary: Embedded map Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
182 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

88% escaped208 total outputs
Attack Surface

TraveledMap Trip itinerary: Embedded map Attack Surface

Entry Points4
Unprotected0

Shortcodes 4

[embedded_trip] src\widget\shortcode.php:51
[embedded_trip_step] src\widget\shortcode.php:52
[embedded_trip] trunk\src\widget\shortcode.php:51
[embedded_trip_step] trunk\src\widget\shortcode.php:52
WordPress Hooks 16
filterblock_categoriessrc\init.php:30
actioninitsrc\init.php:37
actionadd_meta_boxessrc\metabox\metabox.php:8
actionsave_postsrc\metabox\metabox.php:196
actioninitsrc\trip-block\src\index.php:9
actioninitsrc\trip-block\trip-block.php:30
actioninitsrc\trip-step-block\trip-step-block.php:30
actionwidgets_initsrc\widget\widget.php:3
filterblock_categoriestrunk\src\init.php:30
actioninittrunk\src\init.php:37
actionadd_meta_boxestrunk\src\metabox\metabox.php:8
actionsave_posttrunk\src\metabox\metabox.php:196
actioninittrunk\src\trip-block\src\index.php:9
actioninittrunk\src\trip-block\trip-block.php:30
actioninittrunk\src\trip-step-block\trip-step-block.php:30
actionwidgets_inittrunk\src\widget\widget.php:3
Maintenance & Trust

TraveledMap Trip itinerary: Embedded map Maintenance & Trust

Maintenance Signals

WordPress version tested6.6.5
Last updatedDec 18, 2024
PHP min version5.6
Downloads4K

Community Trust

Rating100/100
Number of ratings4
Active installs80
Developer Profile

TraveledMap Trip itinerary: Embedded map Developer Profile

traveledmap

1 plugin · 80 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect TraveledMap Trip itinerary: Embedded map

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/traveledmap-trip-itinerary-embedded-map/src/metabox/style.css
Script Paths
https://cdn.jsdelivr.net/gh/traveledmap/trip-embedder-js@$version/dist/traveledmap-trip.min.js
Version Parameters
plugins/traveledmap-trip-itinerary-embedded-map/src/metabox/style.css?ver=plugins/traveledmap-trip-itinerary-embedded-map/src/trip-block/buildplugins/traveledmap-trip-itinerary-embedded-map/src/trip-step-block/build

HTML / DOM Fingerprints

CSS Classes
traveledmap-stretchable-map
Data Attributes
data-traveledmap-user-iddata-traveledmap-trip-iddata-map-heightdata-standard-map-heightdata-extended-map-heightdata-should-show-pictures+8 more
JS Globals
traveledmap_user_idtraveledmap_trip_idSDK_VERSIONTraveledMap_Utils
Shortcode Output
[traveledmap_map]
FAQ

Frequently Asked Questions about TraveledMap Trip itinerary: Embedded map