
WP_Places Security & Risk Analysis
wordpress.org/plugins/wp-placesWP_Places populates up-to-the-minute information about almost any location or business. Display address, phone number, hours of operation, and website …
Is WP_Places Safe to Use in 2026?
Generally Safe
Score 100/100WP_Places has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-places" v2.1.2 plugin exhibits a generally strong security posture based on the provided static analysis. It has a limited attack surface, with all identified entry points (shortcodes) not explicitly noted as unprotected. The code also demonstrates good practices by using prepared statements for all SQL queries and properly escaping a high percentage of its output. The absence of dangerous functions, file operations, and recorded vulnerabilities is also a positive indicator. The limited number of external HTTP requests is also a good sign. However, the complete absence of nonce checks across all entry points, coupled with only two capability checks for all operations, presents a significant concern. This lack of robust authentication and authorization mechanisms for its shortcode functionality leaves it potentially vulnerable to unauthorized actions if an attacker can trigger these shortcodes. While the vulnerability history is clean, it's important to remember that a clean history doesn't guarantee future safety, especially when fundamental security controls like nonce checks are missing.
Key Concerns
- Missing nonce checks on all entry points
- Limited capability checks across entry points
- Unescaped output (14% of total)
WP_Places Security Vulnerabilities
WP_Places Code Analysis
Output Escaping
WP_Places Attack Surface
Shortcodes 3
WordPress Hooks 25
Maintenance & Trust
WP_Places Maintenance & Trust
Maintenance Signals
Community Trust
WP_Places Alternatives
Widgets for Google Reviews
wp-reviews-plugin-for-google
Embed Google reviews fast and easily into your WordPress site. Increase SEO, trust and sales using Google reviews.
SlimStat Analytics
wp-slimstat
The leading web analytics plugin for WordPress
IP2Location Country Blocker
ip2location-country-blocker
Blocks unwanted visitors from accessing your frontend (blog pages) or backend (admin area) by countries or proxy servers.
WP Google Review Slider
wp-google-places-review-slider
Display Google reviews on your site and even show user images! No address, no problem! Also works with Service Area Businesses and Products! Lightwei …
Geolocation IP Detection
geoip-detect
Provides geographic information detected by an IP adress.
WP_Places Developer Profile
4 plugins · 40 total installs
How We Detect WP_Places
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-places/includes/js/map-shortcode.js/wp-content/plugins/wp-places/includes/js/shortcodes.js/wp-content/plugins/wp-places/includes/css/shortcodes.css/wp-content/plugins/wp-places/includes/js/map-shortcode.js/wp-content/plugins/wp-places/includes/js/shortcodes.jswp-places/includes/js/map-shortcode.js?ver=wp-places/includes/js/shortcodes.js?ver=wp-places/includes/css/shortcodes.css?ver=HTML / DOM Fingerprints
wp-places-map-canvaswp-places-directions-panelwp-places-info-windowdata-wpp-iddata-wpp-latdata-wpp-lngdata-wpp-zoomwp_places_settingswp_places_map_shortcode_params[wp_places_map[wp_places_directions