
WP Mapbox GL JS Maps Security & Risk Analysis
wordpress.org/plugins/wp-mapbox-gl-jsNOTE: This plugin has been deprecated and is no longer supported. Please see our latest plugin, Mapster WP Maps, for a more up-to-date and maintained …
Is WP Mapbox GL JS Maps Safe to Use in 2026?
Use With Caution
Score 63/100WP Mapbox GL JS Maps has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'wp-mapbox-gl-js' v3.0.1 plugin exhibits a generally good security posture with several positive indicators. The complete absence of SQL injection vulnerabilities due to prepared statements and the lack of critical or high-severity taint flows are strong points. Nonce and capability checks are also present, suggesting an awareness of secure coding practices. However, a significant concern arises from the 40% of output that is not properly escaped, presenting a potential cross-site scripting (XSS) risk. Additionally, the plugin has a history of medium-severity vulnerabilities, specifically XSS, and notably has one currently unpatched CVE from 2025. This pattern, combined with the unescaped output, indicates a recurring weakness that attackers could exploit. While the plugin demonstrates strengths in certain areas, the unpatched vulnerability and the significant percentage of unescaped output warrant careful attention.
Key Concerns
- Unpatched CVE
- High percentage of unescaped output
WP Mapbox GL JS Maps Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Mapbox GL JS Maps <= 3.0.1 - Authenticated (Contributor+) Stored Cross-Site Scripting
WP Mapbox GL JS Maps Code Analysis
Output Escaping
Data Flow Analysis
WP Mapbox GL JS Maps Attack Surface
Shortcodes 1
WordPress Hooks 16
Maintenance & Trust
WP Mapbox GL JS Maps Maintenance & Trust
Maintenance Signals
Community Trust
WP Mapbox GL JS Maps Alternatives
Mapster WP Maps
mapster-wp-maps
Mapster WP Maps is the smoothest, easiest way to make maps for your site. No API keys required.
Open User Map
open-user-map
Engage your visitors with an interactive map – let them add markers instantly or create a custom map showcasing your favorite spots.
SimpleMaps
interactive-maps
Easily add an interactive map of the world, US, or many other countries to your WordPress site.
Interactive US Map
interactive-us-map
Interactive US Regional Map WordPress plugin with an easy to use map dashboard.
Interactive US Map – Create Clickable & Customizable U.S. Maps
interactive-map-of-the-us-regions
Create engaging Interactive United States Maps in WordPress for free. It's easy to install, simple, and highly customizable.
WP Mapbox GL JS Maps Developer Profile
1 plugin · 1K total installs
How We Detect WP Mapbox GL JS Maps
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-mapbox-gl-js/css/balloon.css/wp-content/plugins/wp-mapbox-gl-js/css/rc-slider.min.css/wp-content/plugins/wp-mapbox-gl-js/css/wp-mapbox-gl-js-admin.css/wp-content/plugins/wp-mapbox-gl-js/js/wp-mapbox-gl-js-admin.js/wp-content/plugins/wp-mapbox-gl-js/wp-mapmaker/public/css/style.css/wp-content/plugins/wp-mapbox-gl-js/wp-mapmaker/build/static/js/https://api.mapbox.com/mapbox-gl-js/v1.12.0/mapbox-gl.jshttps://api.mapbox.com/mapbox-gl-js/plugins/mapbox-gl-draw/v1.0.4/mapbox-gl-draw.csshttps://api.mapbox.com/mapbox-gl-js/plugins/mapbox-gl-geocoder/v2.2.0/mapbox-gl-geocoder.csshttps://api.mapbox.com/mapbox-gl-js/plugins/mapbox-gl-directions/v3.1.1/mapbox-gl-directions.csshttps://unpkg.com/react-select@1.2.1/dist/react-select.csswp-mapbox-gl-js/css/wp-mapbox-gl-js-admin.css?ver=HTML / DOM Fingerprints
wp-mapbox-gl-js-map-containerdata-mapbox-map-iddata-mapbox-map-tokendata-mapbox-map-styledata-mapbox-map-center-latdata-mapbox-map-center-lngdata-mapbox-map-zoomwp_mapbox_gl_js_paramsparams/wp-json/wp-mapbox-gl-js/v1/map/[mapbox-gl-js-map[mapbox-gl-js-map-layer[mapbox-gl-js-map-marker