
Webby Maps Security & Risk Analysis
wordpress.org/plugins/webby-mapsCreate unlimited maps with custom icon markers and infowindows for free. Furthermore, this plugin does not require API Key to work.
Is Webby Maps Safe to Use in 2026?
Generally Safe
Score 100/100Webby Maps has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'webby-maps' plugin v1.0.0 exhibits a strong security posture in several key areas, particularly with its output escaping and SQL query practices. The static analysis indicates that all 16 observed output operations are properly escaped, and a very high percentage (89%) of the 9 SQL queries utilize prepared statements, which significantly mitigates the risk of common injection vulnerabilities. The absence of external HTTP requests and any recorded CVEs further bolsters its security profile.
However, the analysis reveals critical areas of concern. The plugin has 0 nonce checks and 0 capability checks across its entry points, despite having one shortcode as an entry point. This is a significant vulnerability, as it means any user, regardless of their privileges or if they are logged in, can trigger the functionality associated with the shortcode. The taint analysis shows 2 flows with unsanitized paths, which, while not resulting in critical or high severity findings in this specific version, is a strong indicator of potential path traversal vulnerabilities if the input handling is not robust. The presence of file operations, coupled with unsanitized path flows, warrants careful review to ensure these operations are not exploitable.
In conclusion, while 'webby-maps' v1.0.0 demonstrates good practices in SQL and output handling, the complete lack of authentication and authorization checks on its shortcode is a major security flaw. The unsanitized path flows also represent a latent risk. The absence of past vulnerabilities is positive but does not negate the current risks identified in the code analysis.
Key Concerns
- Missing nonce checks
- Missing capability checks
- Flows with unsanitized paths
- Raw SQL without prepared statements (1 query)
Webby Maps Security Vulnerabilities
Webby Maps Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Webby Maps Attack Surface
Shortcodes 1
WordPress Hooks 12
Maintenance & Trust
Webby Maps Maintenance & Trust
Maintenance Signals
Community Trust
Webby Maps Alternatives
Events Manager – OpenStreetMaps
stonehenge-em-osm
OpenStreetMaps for Events Manager. An add-on to replace Google Maps with OpenStreetMap. 0% Google, 100% open source.
WP Go Maps (formerly WP Google Maps)
wp-google-maps
The easiest to use Google maps plugin! Create a custom Google map, map block, store locator or map widget with high quality markers containing categor …
Instant Images – One-click Image Uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy
instant-images
One-click uploads from Unsplash, Openverse, Pixabay, Pexels, and Giphy directly to your WordPress media library.
reSmush.it : The original free image compressor and optimizer plugin
resmushit-image-optimizer
reSmush.it is the FREE image compressor and optimizer plugin - use it to optimize your images and improve the SEO and performance of your website.
Robin Image Optimizer – Unlimited Image Optimization & WebP Converter
robin-image-optimizer
Unlimited automatic image optimization for WordPress. Compress images, convert to WebP, and improve site speed without losing image quality.
Webby Maps Developer Profile
2 plugins · 10 total installs
How We Detect Webby Maps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webby-maps/dist/templates/ListMaps.css/wp-content/plugins/webby-maps/dist/templates/ListMaps.js/wp-content/plugins/webby-maps/dist/css/leaflet-1.7.1.min.css/wp-content/plugins/webby-maps/dist/templates/EditMap.css/wp-content/plugins/webby-maps/dist/templates/AddMap.js/wp-content/plugins/webby-maps/dist/templates/ListMaps.js/wp-content/plugins/webby-maps/dist/templates/AddMap.jswebbymaps-listmapswebbymaps-addmapleafletHTML / DOM Fingerprints
data-mapidwebbymaps