
Waymark Security & Risk Analysis
wordpress.org/plugins/waymarkWaymark adds powerful mapping features to WordPress that are easy to use. Create beautiful, interactive Maps customised to suit your needs.
Is Waymark Safe to Use in 2026?
Generally Safe
Score 96/100Waymark has a strong security track record. Known vulnerabilities have been patched promptly.
The 'waymark' plugin v1.5.9 demonstrates a mixed security posture. On the positive side, it utilizes prepared statements for all SQL queries and implements nonce checks and capability checks for its entry points, which are good security practices. The static analysis shows a relatively small attack surface with all AJAX handlers having authentication checks. Taint analysis did not reveal critical or high severity issues, and there are no currently unpatched CVEs.
However, several concerns warrant attention. The plugin has a history of 4 known medium-severity CVEs, including SSRF and XSS, indicating past vulnerabilities that, while currently patched, suggest a pattern of potential security weaknesses. The taint analysis identified 2 flows with unsanitized paths, which could potentially lead to security issues if not handled carefully. Furthermore, the output escaping is not perfect, with 12% of outputs not being properly escaped, increasing the risk of XSS vulnerabilities.
In conclusion, while the plugin employs some sound security measures and currently has no critical unpatched vulnerabilities, the history of medium-severity flaws and the presence of unsanitized paths and imperfect output escaping indicate areas where further scrutiny and improvement are needed to ensure a robust security posture.
Key Concerns
- History of medium severity CVEs (4 total)
- Flows with unsanitized paths identified
- Output escaping not fully implemented (12% unescaped)
Waymark Security Vulnerabilities
CVEs by Year
Severity Breakdown
4 total CVEs
Waymark <= 1.5.2 - Authenticated (Contributor+) Server-Side Request Forgery
Waymark <= 1.5.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
Waymark <= 1.5.0 - Authenticated (Contributor+) Stored Cross-Site Scripting
Waymark <= 1.4.1 - Reflected Cross-Site Scripting via 'content'
Waymark Code Analysis
Output Escaping
Data Flow Analysis
Waymark Attack Surface
AJAX Handlers 3
WordPress Hooks 39
Maintenance & Trust
Waymark Maintenance & Trust
Maintenance Signals
Community Trust
Waymark Alternatives
GPX Viewer
gpx-viewer
Display GPX tracks with their elevation profile on OSM maps, edit them interactively
Shiprocket
shiprocket
Auto Sync your Woocommerce store orders & ship them at lowest shipping rates. Automate your shipping, save time & money.
Lf Hiker
lf-hiker
Lf Hiker is a plugin for quickly display your gpx tracks with their profile elevation on an interactive map.
Redx for WooCommerce
redx-for-woocommerce
The "Redx for WooCommerce" plugin integrates Redx logistics services into your WooCommerce store. Seamlessly track your orders, manage shipm …
ILS – Indian Logistics Services
ils-indian-logistics-services
Process your orders in bulk and create tracking numbers for your orders, Notify your customers and print label, invoices.
Waymark Developer Profile
3 plugins · 4K total installs
How We Detect Waymark
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/waymark/css/admin.min.css/wp-content/plugins/waymark/waymark-js/dist/css/waymark-js.min.css/wp-content/plugins/waymark/waymark-js/dist/js/waymark-js.js/wp-content/plugins/waymark/waymark-js/dist/js/waymark-js.min.js/wp-content/plugins/waymark/js/admin.min.js/wp-content/plugins/waymark/js/admin.min.js/wp-content/plugins/waymark/waymark-js/dist/js/waymark-js.js/wp-content/plugins/waymark/waymark-js/dist/js/waymark-js.min.jswaymark/style.css?ver=waymark_admin_css?ver=waymark-js?ver=waymark_admin_js?ver=HTML / DOM Fingerprints
waymark-mapwaymark-inputwaymark-input-map_dataSTART Waymark Head CSSEND Waymark Head CSSSTART Waymark Footer JSEND Waymark Footer JSid="waymark-map"id="waymark-data"waymark_php_langwaymark_user_configwaymark_editorwindow.Waymark_Map_Factorywaymark_jswaymark_setup_map_editor