
User Map Security & Risk Analysis
wordpress.org/plugins/usermapEnable you to display how many users are online and registered on your Wordpress blog .
Is User Map Safe to Use in 2026?
Generally Safe
Score 85/100User Map has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The usermap plugin v1.2.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for all SQL queries and has no recorded vulnerability history, suggesting a stable and previously secure codebase. The absence of dangerous functions, external HTTP requests, and bundled libraries further contributes to its strengths.
However, significant concerns arise from the attack surface. With a total of 5 entry points, a disproportionate 4 (80%) lack authentication checks. Specifically, 4 AJAX handlers are unprotected, presenting a direct pathway for malicious input. The taint analysis reveals 2 flows with unsanitized paths, indicating potential vulnerabilities related to handling user-supplied data, although these did not reach critical or high severity in the analysis. The lack of nonce checks on these unprotected AJAX handlers is a critical omission, making them susceptible to Cross-Site Request Forgery (CSRF) attacks. Furthermore, only 55% of output escaping is properly implemented, raising concerns about Cross-Site Scripting (XSS) vulnerabilities.
In conclusion, while the plugin benefits from secure database interactions and a clean history, the extensive unprotected attack surface, particularly the AJAX endpoints, and the moderate rate of output escaping are substantial weaknesses. The presence of unsanitized paths in taint analysis, even without critical severity, warrants attention. The plugin's security would be significantly enhanced by implementing robust authentication and capability checks on all entry points, particularly the AJAX handlers, and improving output escaping practices.
Key Concerns
- Unprotected AJAX handlers
- Unsanitized paths in taint flows
- Missing nonce checks on AJAX
- Moderate output escaping
- Limited capability checks
User Map Security Vulnerabilities
User Map Release Timeline
User Map Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
User Map Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 11
Scheduled Events 1
Maintenance & Trust
User Map Maintenance & Trust
Maintenance Signals
Community Trust
User Map Alternatives
WP Go Maps (formerly WP Google Maps)
wp-google-maps
The easiest to use Google maps plugin! Create a custom Google map, map block, store locator or map widget with high quality markers containing categor …
iframe
iframe
[iframe src="http://www.youtube.com/embed/7_nAZQt9qu0" width="100%" height="500"] shortcode
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
WP Store Locator
wp-store-locator
An easy to use location management system that enables users to search for nearby physical stores.
API KEY for Google Maps
api-key-for-google-maps
Retroactively add Google Maps API KEY to any theme or plugin.
User Map Developer Profile
6 plugins · 110 total installs
How We Detect User Map
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/usermap/js/script.js/wp-content/plugins/usermap/css/style.css/wp-content/plugins/usermap/js/script.jsusermap/style.css?ver=usermap/script.js?ver=HTML / DOM Fingerprints
data-marker-latdata-marker-lngajaxurlusermap