
Very Simple Google Maps Security & Risk Analysis
wordpress.org/plugins/very-simple-google-mapsContains a simple way to add an embedded Google Map to any page or post.
Is Very Simple Google Maps Safe to Use in 2026?
Generally Safe
Score 91/100Very Simple Google Maps has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "very-simple-google-maps" plugin v2.9.1 exhibits a generally good security posture based on the static analysis. The code demonstrates adherence to best practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and properly escaping all detected outputs. The absence of file operations and external HTTP requests further reduces the attack surface. Furthermore, no taint analysis issues were identified, suggesting that sensitive data is not being improperly handled within the analyzed code paths.
However, the plugin's vulnerability history is a significant concern. With two known medium-severity CVEs, both attributed to Cross-Site Scripting (XSS), it indicates a recurring pattern of input sanitization or output escaping issues in the past. While there are currently no unpatched vulnerabilities, the historical presence of XSS flaws suggests that developers should remain vigilant. The lack of nonce checks and capability checks on its single shortcode entry point, while not currently exploited in a way that appears in the static analysis or taint flows, represents a potential weakness that could be leveraged in conjunction with other vulnerabilities or in future iterations of the plugin.
In conclusion, the plugin's current code is well-written with respect to database interaction and output handling. The primary risk stems from its past vulnerability history, particularly the repeated occurrence of XSS. The absence of explicit nonce and capability checks on its shortcode, though not flagged as an immediate critical issue by the static analysis, is a point of concern that contributes to a slightly elevated risk profile. Users should ensure they are on the latest version and be aware of the historical context.
Key Concerns
- History of 2 medium severity CVEs
- Shortcode without nonce checks
- Shortcode without capability checks
Very Simple Google Maps Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Very Simple Google Maps <= 2.9 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
Very Simple Google Maps <= 2.8.4 - Authenticated (Contributor+) Stored Cross Site Scripting
Very Simple Google Maps Release Timeline
Very Simple Google Maps Code Analysis
Output Escaping
Very Simple Google Maps Attack Surface
Shortcodes 1
Maintenance & Trust
Very Simple Google Maps Maintenance & Trust
Maintenance Signals
Community Trust
Very Simple Google Maps Alternatives
Simple Google Contact Map
simple-google-contact-map
Simple embedded Google Map to any Post or Page Using shortcode and Widget.
WP Store Locator
wp-store-locator
An easy to use location management system that enables users to search for nearby physical stores.
Store Locator WordPress
agile-store-locator
Agile Store Locator is a premium store finder plugin designed to offer you immediate access to all the best stores in your local area.
Contact Form 7 extension for Google Map fields
cf7-google-map
This plugin enables the insertion of google maps into contact form 7 as an input field.
Contact Page
contact-page
Easily create a contact page with relevant address information, Google Maps, your latest tweets and links to relevant social media profiles.
Very Simple Google Maps Developer Profile
2 plugins · 5K total installs
How We Detect Very Simple Google Maps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
vsg-map<div class="vsg-map"><iframe align="