
Treweler Map Builder Security & Risk Analysis
wordpress.org/plugins/treweler-map-builderThe Treweler plugin is a multifunction map builder. Its purpose is to help you create an interactive map for your personal or business project.
Is Treweler Map Builder Safe to Use in 2026?
Generally Safe
Score 100/100Treweler Map Builder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'treweler-map-builder' plugin v1.02 exhibits a mixed security posture. On the positive side, it demonstrates strong practices in SQL query handling, utilizing prepared statements exclusively, and a significant majority of its output is properly escaped. The absence of known CVEs and a clean vulnerability history are also encouraging indicators. However, there are notable concerns regarding its attack surface. The plugin exposes three AJAX handlers, two of which lack authentication checks. This, combined with two unsanitized taint flows, presents potential entry points for malicious actors. The use of 'unserialize' without apparent sanitization in the code signals a potential risk for deserialization vulnerabilities, especially if untrusted data is passed to it. While the current vulnerability history is clean, the presence of these code-level weaknesses suggests that future vulnerabilities are possible if not addressed. Overall, the plugin has strengths in its data handling but requires attention to its access control and potential deserialization risks.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized taint flows found
- Use of 'unserialize' dangerous function
- Bundled libraries (Select2, Guzzle)
Treweler Map Builder Security Vulnerabilities
Treweler Map Builder Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Treweler Map Builder Attack Surface
AJAX Handlers 3
WordPress Hooks 85
Scheduled Events 1
Maintenance & Trust
Treweler Map Builder Maintenance & Trust
Maintenance Signals
Community Trust
Treweler Map Builder Alternatives
MapGeo – Interactive Geo Maps
interactive-geo-maps
Create interactive vector maps of the world, continents, any country in the world and specific regions, including individual US state county maps.
Open User Map
open-user-map
Engage your visitors with an interactive map – let them add markers instantly or create a custom map showcasing your favorite spots.
Mapster WP Maps
mapster-wp-maps
Mapster WP Maps is the smoothest, easiest way to make maps for your site. No API keys required.
WP Mapbox GL JS Maps
wp-mapbox-gl-js
NOTE: This plugin has been deprecated and is no longer supported. Please see our latest plugin, Mapster WP Maps, for a more up-to-date and maintained …
Store Locations Map
store-locations-map
Display an interactive map of store locations using shortcodes. Easily add customizable markers, titles, images, descriptions, and links to your posts
Treweler Map Builder Developer Profile
1 plugin · 80 total installs
How We Detect Treweler Map Builder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/treweler-map-builder/assets/css/treweler-free.css/wp-content/plugins/treweler-map-builder/assets/css/treweler-admin-new.css/wp-content/plugins/treweler-map-builder/assets/css/treweler-admin-markers.css/wp-content/plugins/treweler-map-builder/assets/css/treweler-admin.css/wp-content/plugins/treweler-map-builder/assets/js/treweler-mapbox.js/wp-content/plugins/treweler-map-builder/assets/js/treweler-helpers.js/wp-content/plugins/treweler-map-builder/assets/js/treweler-script.jshttps://api.mapbox.com/mapbox-gl-js/v3.0.0-beta.5/mapbox-gl.jshttps://api.mapbox.com/mapbox-gl-js/plugins/mapbox-gl-geocoder/v5.0.0/mapbox-gl-geocoder.min.jshttps://api.mapbox.com/mapbox-gl-js/plugins/mapbox-gl-draw/v1.4.2/mapbox-gl-draw.jstreweler-map-builder/assets/css/treweler-free.css?ver=treweler-map-builder/assets/css/treweler-admin-new.css?ver=treweler-map-builder/assets/css/treweler-admin-markers.css?ver=treweler-map-builder/assets/css/treweler-admin.css?ver=treweler-map-builder/assets/js/treweler-mapbox.js?ver=treweler-map-builder/assets/js/treweler-helpers.js?ver=treweler-map-builder/assets/js/treweler-script.js?ver=HTML / DOM Fingerprints
twer-hidden-wp-editordata-slug="treweler"TWERTWER_IS_FREETWER_VERSION