
WP Open Street Map Security & Risk Analysis
wordpress.org/plugins/wp-open-street-mapCreate easily maps with OpenStreetMap
Is WP Open Street Map Safe to Use in 2026?
Generally Safe
Score 100/100WP Open Street Map has a strong security track record. Known vulnerabilities have been patched promptly.
The 'wp-open-street-map' plugin v1.35 exhibits a generally strong security posture with excellent adherence to secure coding practices. The static analysis reveals a minimal attack surface, with only one shortcode as an entry point and no unprotected handlers or routes. The code demonstrates responsible handling of SQL queries, with a high percentage using prepared statements, and an impressive 99% of output being properly escaped, significantly mitigating common web vulnerabilities like Cross-Site Scripting (XSS). The plugin also incorporates a respectable number of nonce and capability checks, further bolstering its defenses. The absence of file operations and external HTTP requests also reduces potential attack vectors.
Despite these strengths, there is a past vulnerability history, including one medium-severity CVE, which was reported in October 2023. While the plugin currently has no unpatched CVEs, this history indicates a pattern of past security weaknesses, specifically related to Cross-Site Request Forgery (CSRF). Although the current analysis shows no critical or high-severity taint flows and no unsanitized paths, the past CSRF vulnerability, if it was not addressed through input validation or nonce checks on its entry points, could still represent a latent risk if not fully remediated or if similar vulnerabilities arise in the future.
In conclusion, 'wp-open-street-map' v1.35 is a well-developed plugin from a security perspective, demonstrating a commitment to secure coding. Its robust output escaping, prepared SQL statements, and limited attack surface are significant strengths. However, the presence of a past medium-severity CSRF vulnerability, even if patched, warrants a degree of caution and ongoing vigilance. Future development should continue to prioritize input validation and secure handling of all user-submitted data, especially in the context of its single shortcode entry point.
Key Concerns
- Past medium severity CVE (CSRF)
WP Open Street Map Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
WP Open Street Map <= 1.25 - Cross-Site Request Forgery via wp_openstreetmaps
WP Open Street Map Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Open Street Map Attack Surface
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
WP Open Street Map Maintenance & Trust
Maintenance Signals
Community Trust
WP Open Street Map Alternatives
OSM – OpenStreetMap
osm
Customize maps in your post, pages and widgets. GPX, KML and more. The easy way to map!
ShMapper by Teplitsa
shmapper-by-teplitsa
shMapper is a plugin, that allows you to create simple crowdsourcing maps based on OpenStreetMap and Yandex.Maps.
Custom Post Type to Map Store
cpt-to-map-store
An another Store Locator on WordPress but with OpenStreetMap & Leaflet and Meta Fields
ACF OpenStreetMap Field into a Block
acf-openstreetmap-field-block
Very simple plugin that adds an OpenStreetMap ACF block to the WordPress block editor.
MapBBCode for WordPress
mapbb
MapBB-shortcodes [map] for Leaflet based maps.
WP Open Street Map Developer Profile
17 plugins · 27K total installs
How We Detect WP Open Street Map
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-open-street-map/css/admin.cssHTML / DOM Fingerprints
data-wp-osm-map-id[wp-osm id=