WP Google Street View (with 360° virtual tour) & Google maps + Local SEO Security & Risk Analysis

wordpress.org/plugins/wp-google-street-view

The WP Google Street View allows you to embed Google street View (with virtual tour) & Google Maps maps with high quality markers.

400 active installs v1.1.9 PHP 7.4+ WP 4.1+ Updated Jan 4, 2026
google-mapsgoogle-street-viewmap-markersmapsvirtual-tour
96
A · Safe
CVEs total3
Unpatched0
Last CVEJan 8, 2026
Safety Verdict

Is WP Google Street View (with 360° virtual tour) & Google maps + Local SEO Safe to Use in 2026?

Generally Safe

Score 96/100

WP Google Street View (with 360° virtual tour) & Google maps + Local SEO has a strong security track record. Known vulnerabilities have been patched promptly.

3 known CVEsLast CVE: Jan 8, 2026Updated 2mo ago
Risk Assessment

The wp-google-street-view plugin version 1.1.9 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and performing nonce and capability checks on its identified entry points, which are limited to two shortcodes. The absence of AJAX handlers, REST API routes, and cron events, as well as zero file operations and external HTTP requests, significantly reduces the attack surface. However, a notable concern is the low percentage of properly escaped output (32%), suggesting a potential for Cross-Site Scripting (XSS) vulnerabilities, especially given the plugin's history of such issues.

The plugin's vulnerability history reveals a pattern of medium-severity XSS vulnerabilities, with the last recorded vulnerability in 2026. While there are currently no unpatched CVEs, the recurring nature of XSS issues indicates a need for more rigorous output sanitization and validation in the codebase. The presence of a bundled Freemius library at version 1.0, while not explicitly stated as vulnerable, could also pose a risk if it contains known security flaws that have not been updated.

In conclusion, while the plugin has made strides in securing its entry points and database interactions, the significant amount of unescaped output remains a critical weakness. The historical trend of XSS vulnerabilities further amplifies this concern. Users should be aware of the potential for XSS attacks and monitor for future updates that address output sanitization more thoroughly.

Key Concerns

  • Significant percentage of unescaped output
  • Bundled outdated library (Freemius v1.0)
  • History of medium severity XSS vulnerabilities
Vulnerabilities
3

WP Google Street View (with 360° virtual tour) & Google maps + Local SEO Security Vulnerabilities

CVEs by Year

2 CVEs in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
3

3 total CVEs

CVE-2026-0563medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Google Street View (with 360° virtual tour) & Google maps + Local SEO <= 1.1.8 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpgsv_map' Shortcode

Jan 8, 2026 Patched in 1.1.9 (1d)
CVE-2025-30799medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Google Street View <= 1.1.5 - Authenticated (Administrator+) Stored Cross-Site Scripting

Mar 27, 2025 Patched in 1.1.6 (7d)
CVE-2024-13542medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

WP Google Street View (with 360° virtual tour) & Google maps + Local SEO <= 1.1.3 - Authenticated (Contributor+) Stored Cross-Site Scripting

Jan 23, 2025 Patched in 1.1.4 (1d)
Code Analysis
Analyzed Mar 16, 2026

WP Google Street View (with 360° virtual tour) & Google maps + Local SEO Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
150
69 escaped
Nonce Checks
2
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

32% escaped219 total outputs
Attack Surface

WP Google Street View (with 360° virtual tour) & Google maps + Local SEO Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[wpgsv] includes\shortcode.php:82
[wpgsv_map] includes\shortcode.php:142
WordPress Hooks 26
actioninitadmin\cpt.php:51
actioninitadmin\cpt.php:90
actionrestrict_manage_postsadmin\cpt.php:114
filterparse_queryadmin\cpt.php:125
filtermanage_wpgsv_category_custom_columnadmin\cpt.php:141
actionadmin_enqueue_scriptsadmin\inc\assets.php:24
actionwp_enqueue_mediaadmin\inc\assets.php:34
actionedit_form_topadmin\inc\metabox_shortcode.php:23
filtermanage_wpgsv_posts_columnsadmin\inc\metabox_shortcode.php:28
actionmanage_wpgsv_posts_custom_columnadmin\inc\metabox_shortcode.php:36
actionadd_meta_boxesadmin\metabox.php:3
actionadd_meta_boxesadmin\metabox.php:18
actionsave_postadmin\metabox.php:56
actionadd_meta_boxesadmin\metabox.php:106
actionadd_meta_boxesadmin\metabox.php:124
actionadmin_menuadmin\settings.php:18
actionmedia_buttonsincludes\shortcode_button.php:3
actionadmin_footerincludes\shortcode_button.php:33
actionwp_headincludes\structured_data.php:100
filterconnect_urlwp-google-street-view.php:67
filterafter_skip_urlwp-google-street-view.php:68
filterafter_connect_urlwp-google-street-view.php:69
filterafter_pending_connect_urlwp-google-street-view.php:70
filterconnect_messagewp-google-street-view.php:86
filterplugin_iconwp-google-street-view.php:96
actioninitwp-google-street-view.php:152
Maintenance & Trust

WP Google Street View (with 360° virtual tour) & Google maps + Local SEO Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 4, 2026
PHP min version7.4
Downloads12K

Community Trust

Rating74/100
Number of ratings3
Active installs400
Developer Profile

WP Google Street View (with 360° virtual tour) & Google maps + Local SEO Developer Profile

Pagup

17 plugins · 33K total installs

78
trust score
Avg Security Score
98/100
Avg Patch Time
439 days
View full developer profile
Detection Fingerprints

How We Detect WP Google Street View (with 360° virtual tour) & Google maps + Local SEO

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-google-street-view/assets/css/flexboxgrid.min.css/wp-content/plugins/wp-google-street-view/assets/css/admin.css/wp-content/plugins/wp-google-street-view/assets/js/admin.js
Script Paths
/wp-content/plugins/wp-google-street-view/assets/js/admin.js

HTML / DOM Fingerprints

CSS Classes
wpgsv-admin-wrapwpgsv-map-editor-wrapwpgsv-map-itemwpgsv-map-preview
HTML Comments
<!-- shortcode --><!-- shortcode_button --><!-- structured_data --><!-- admin -->+1 more
Data Attributes
data-wpgsv-marker-icondata-wpgsv-marker-latdata-wpgsv-marker-lngdata-wpgsv-marker-titledata-wpgsv-map-latdata-wpgsv-map-lng+2 more
JS Globals
wpgsv_map_settingswpgsv_map_dataWPGSV_AJAX_URL
Shortcode Output
[wpgsv_map][wpgsv_street_view]
FAQ

Frequently Asked Questions about WP Google Street View (with 360° virtual tour) & Google maps + Local SEO