
WP Google Maps Shortcode Security & Risk Analysis
wordpress.org/plugins/wp-google-maps-shortcodeInsert Google Maps into your post or page using Shortcode
Is WP Google Maps Shortcode Safe to Use in 2026?
Generally Safe
Score 85/100WP Google Maps Shortcode has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wp-google-maps-shortcode plugin v1.2 exhibits a generally good security posture based on the provided static analysis. The absence of known vulnerabilities, critical taint flows, and dangerous functions is a positive indicator. The plugin also exclusively uses prepared statements for SQL queries, which is a strong security practice. However, several concerns warrant attention. The significant portion of improperly escaped output (50%) presents a potential risk for cross-site scripting (XSS) vulnerabilities, especially when combined with the lack of capability checks and nonce verification for its single shortcode entry point. While the attack surface is small (1 entry point), the lack of protective measures around it is a weakness. The single external HTTP request, without context, could also pose a risk if the target is compromised or if the request is not properly validated. The plugin's clean vulnerability history is reassuring, but it doesn't negate the risks identified in the current code analysis.
Key Concerns
- 50% of output not properly escaped
- No capability checks on entry points
- No nonce checks on entry points
- External HTTP request without context
WP Google Maps Shortcode Security Vulnerabilities
WP Google Maps Shortcode Code Analysis
Output Escaping
WP Google Maps Shortcode Attack Surface
Shortcodes 1
WordPress Hooks 1
Maintenance & Trust
WP Google Maps Shortcode Maintenance & Trust
Maintenance Signals
Community Trust
WP Google Maps Shortcode Alternatives
Simple Shortcode for Google Maps
simple-google-maps-short-code
A simple shortcode for embedding Google Maps in any WordPress post, page or widget.
Map Engine – Google Maps and Open Street Maps for WordPress
map-engine
An Ultimate map tool to revolutionize your map building experience.
User Map
usermap
Enable you to display how many users are online and registered on your Wordpress blog .
Geolocate My Posts
geolocate-my-posts
A Wordpress plugin that tags the location of your posts using the Google Maps API.
LB GMaps
lb-gmaps
Just another Google Maps plugin but simpler and with a live preview.
WP Google Maps Shortcode Developer Profile
1 plugin · 200 total installs
How We Detect WP Google Maps Shortcode
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-google-maps-shortcode/wp-gmaps-shortcode.php//maps.google.com/maps/api/js?sensor=falseHTML / DOM Fingerprints
wp_gmaps_canvasmap_marker_infowindow_geocoderwp_gmaps_<div class="wp_gmaps_canvas"var map_var marker_var infowindow_