
WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map by aBlocks Security & Risk Analysis
wordpress.org/plugins/wp-map-blockNo API key is required to launch Google Maps & OpenStreetMap.
Is WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map by aBlocks Safe to Use in 2026?
Generally Safe
Score 98/100WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map by aBlocks has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "wp-map-block" plugin v2.0.4 exhibits a mixed security posture. On the positive side, the code demonstrates strong practices in handling SQL queries (100% prepared statements), a high rate of output escaping (96%), and the absence of dangerous functions, file operations, and bundled libraries. The presence of nonce and capability checks, along with a low number of total flows analyzed with no high-severity taint issues, are also positive indicators. However, a significant concern arises from the presence of one unprotected AJAX handler, representing a direct entry point into the plugin's functionality without any authentication or authorization checks. This could potentially be exploited by unauthenticated users.
The vulnerability history reveals two previously disclosed medium-severity Cross-Site Scripting (XSS) vulnerabilities. While there are currently no unpatched CVEs, the past occurrence of XSS suggests a pattern where improper neutralization of input has been an issue. The most recent vulnerability was in 2025, which might imply a relatively recent but resolved security concern. The lack of critical or high-severity vulnerabilities in the history and code analysis is encouraging, but the unprotected AJAX handler and past XSS issues warrant careful consideration.
In conclusion, the plugin has commendable security practices in many areas, particularly concerning database interactions and output sanitization. Nevertheless, the unprotected AJAX endpoint is a notable weakness that could expose the plugin to attacks. The historical XSS vulnerabilities, though resolved, highlight the importance of continued vigilance in input validation. Organizations should monitor this plugin for future updates and potential new vulnerabilities.
Key Concerns
- Unprotected AJAX handler found
- Past medium severity XSS vulnerabilities
WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map by aBlocks Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Map Block <= 2.0.2 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map <= 1.2.2 - Stored Cross-Site Scripting
WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map by aBlocks Release Timeline
WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map by aBlocks Code Analysis
Output Escaping
Data Flow Analysis
WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map by aBlocks Attack Surface
AJAX Handlers 1
WordPress Hooks 10
Maintenance & Trust
WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map by aBlocks Maintenance & Trust
Maintenance Signals
Community Trust
WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map by aBlocks Alternatives
Map Block for Google Maps
map-block-gutenberg
Map block for Gutenberg editor powered by Google Maps. Simple. Fast. Just a map block.
Geomap – Google Map Block
geomap-block
Simple Google Map Block for WordPress – Add a map to the block editor, no API key required.
Advanced Maps Block
advanced-maps-block
Easy to use Google Maps block for the WordPress block editor featuring multiple map markers and unlimited style options.
WE – Google Map Gutenberg Block
we-google-map-block
WE - Google Map Gutenberg Block for Gutenberg editor powered by Google Maps. Simple. Fast. User Friendly. Contact us if you need any help.
Gmap Block
gmap-block
Easily Embed Google map in Gutenberg editor without any API key.
WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map by aBlocks Developer Profile
1 plugin · 20K total installs
How We Detect WP Map Block – Gutenberg Map Block for Google Map and OpenStreet Map by aBlocks
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-map-block/assets/css/frontend.css/wp-content/plugins/wp-map-block/assets/css/wp-map-block-editor.css/wp-content/plugins/wp-map-block/assets/js/frontend.js/wp-content/plugins/wp-map-block/assets/js/leaflet.js/wp-content/plugins/wp-map-block/assets/js/leaflet-fullscreen.js/wp-content/plugins/wp-map-block/assets/js/frontend.js/wp-content/plugins/wp-map-block/assets/js/leaflet.js/wp-content/plugins/wp-map-block/assets/js/leaflet-fullscreen.jswp-map-block/style.css?ver=wp-map-block/script.js?ver=HTML / DOM Fingerprints
wpmapblockrenderdata-settingswpmapblock<div
id="data-settings='' class="wpmapblockrender"style="