WP Mapa Politico España Security & Risk Analysis

wordpress.org/plugins/wp-mapa-politico-spain

Inserta una imagen de un mapa político de España, con áreas definidas sobre las provincias sobre las que se pueden definir hipervínculos.

400 active installs v3.8.1 PHP 5.2.4+ WP 4.6+ Updated May 7, 2025
comunidadesespanamapaprovincias
98
A · Safe
CVEs total2
Unpatched0
Last CVEMay 19, 2025
Safety Verdict

Is WP Mapa Politico España Safe to Use in 2026?

Generally Safe

Score 98/100

WP Mapa Politico España has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: May 19, 2025Updated 11mo ago
Risk Assessment

The "wp-mapa-politico-spain" plugin v3.8.1 presents a mixed security posture. On the positive side, the static analysis reveals strong coding practices. There are no dangerous functions identified, all SQL queries utilize prepared statements, and all output is properly escaped. Furthermore, the plugin demonstrates a very limited attack surface with only one shortcode and no AJAX handlers or REST API routes exposed without proper authentication or permission checks. The taint analysis also shows no critical or high severity flows with unsanitized paths, indicating good input handling within the analyzed code paths.

However, the plugin's historical vulnerability record raises significant concerns. With two known medium-severity CVEs, even though they are currently patched, this suggests a history of exploitable flaws. The common vulnerability types, Cross-Site Request Forgery (CSRF) and Cross-site Scripting (XSS), are indicative of potential weaknesses in how user input is handled or how actions are validated, despite the current static analysis showing no issues in these areas. The most recent vulnerability being dated in 2025 also implies potential for future discoveries or that the listed CVEs might be older and not reflective of the current codebase's state without a more granular look at the specific CVEs and their resolutions. While the current version appears to have addressed past issues, the history warrants vigilance.

In conclusion, "wp-mapa-politico-spain" v3.8.1 exhibits good current development practices with a small attack surface and robust input sanitization in its analyzed code. This is a significant strength. However, its past vulnerability history, particularly the presence of medium-severity CSRF and XSS issues, cannot be overlooked. This suggests that developers should remain vigilant and consider thorough security audits for this plugin, especially if significant updates or new features are introduced. The plugin's external HTTP request without explicit mention of its purpose or validation also warrants a minor point of attention.

Key Concerns

  • Two known medium-severity CVEs historically
  • External HTTP request without clear context
Vulnerabilities
2

WP Mapa Politico España Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-48259medium · 4.3Cross-Site Request Forgery (CSRF)

WP Mapa Politico España <= 3.8.0 - Cross-Site Request Forgery

May 19, 2025 Patched in 3.8.1 (10d)
CVE-2021-24609medium · 5.5Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Mapa Politico España < 3.7.0 - Stored Cross-Site Scripting

Aug 5, 2021 Patched in 3.7.0 (901d)
Code Analysis
Analyzed Mar 16, 2026

WP Mapa Politico España Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
54 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped54 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
settings_page (includes\class-wp-mapa-politico-settings.php:310)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

WP Mapa Politico España Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[wpmps-map] includes\shortcodes.php:3
WordPress Hooks 9
actioninitincludes\class-wp-mapa-politico-settings.php:45
actionadmin_initincludes\class-wp-mapa-politico-settings.php:48
actionadmin_menuincludes\class-wp-mapa-politico-settings.php:51
actionadmin_enqueue_scriptsincludes\class-wp-mapa-politico.php:100
actionadmin_enqueue_scriptsincludes\class-wp-mapa-politico.php:101
filterplugin_row_metaincludes\class-wp-mapa-politico.php:110
filterwpmps_establecer_links_provinciasincludes\shortcodes.php:215
filterwpmps_provincia_linkincludes\shortcodes.php:222
filterwpmps_map_provincias_styleincludes\shortcodes.php:225
Maintenance & Trust

WP Mapa Politico España Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMay 7, 2025
PHP min version5.2.4
Downloads17K

Community Trust

Rating100/100
Number of ratings26
Active installs400
Developer Profile

WP Mapa Politico España Developer Profile

Juan Carlos

2 plugins · 450 total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
456 days
View full developer profile
Detection Fingerprints

How We Detect WP Mapa Politico España

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wp-mapa-politico-spain/js/settings.js
Script Paths
/wp-content/plugins/wp-mapa-politico-spain/js/settings.js
Version Parameters
wp-mapa-politico-spain/style.css?ver=wp-mapa-politico-spain/js/settings.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-token
JS Globals
WP_Mapa_Politico
Shortcode Output
[mapa_politico_spain]
FAQ

Frequently Asked Questions about WP Mapa Politico España