
Store Locator for WordPress Posts Security & Risk Analysis
wordpress.org/plugins/wp-post-store-locatorThis is a wordpress store locator plugin for posts. We can setup stores for individual posts/products.
Is Store Locator for WordPress Posts Safe to Use in 2026?
Generally Safe
Score 85/100Store Locator for WordPress Posts has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-post-store-locator" v1.1 plugin exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for SQL queries and having no known historical vulnerabilities (CVEs). The absence of file operations and external HTTP requests is also a plus. However, significant concerns arise from the attack surface analysis, with a substantial portion of its entry points being unprotected.
Specifically, 4 out of 5 identified entry points (AJAX handlers and shortcodes) lack authentication checks. While the taint analysis did not reveal critical or high severity issues, a flow with unsanitized paths is present, which could potentially be exploited in conjunction with an unprotected entry point. The 71% output escaping rate, while not ideal, is also a point of concern, suggesting a risk of cross-site scripting (XSS) vulnerabilities if the unescaped outputs are user-controlled.
In conclusion, the plugin's clean vulnerability history is a strength, indicating diligent maintenance or a lack of past exploitable flaws. However, the presence of unprotected AJAX handlers and a taint flow with unsanitized paths are serious weaknesses that expose the site to potential attacks, particularly unauthorized actions or XSS. The moderate output escaping rate further adds to the risk profile.
Key Concerns
- 4 unprotected AJAX handlers
- 1 unsanitized path taint flow
- 29% improperly escaped output
- 1 unprotected shortcode
- 0 capability checks
Store Locator for WordPress Posts Security Vulnerabilities
Store Locator for WordPress Posts Code Analysis
Output Escaping
Data Flow Analysis
Store Locator for WordPress Posts Attack Surface
AJAX Handlers 4
Shortcodes 1
WordPress Hooks 6
Maintenance & Trust
Store Locator for WordPress Posts Maintenance & Trust
Maintenance Signals
Community Trust
Store Locator for WordPress Posts Alternatives
Store Locator for WordPress📍
storelocator
Create a store locator for your website in minutes. Add all the store locations in google sheets and embed map on your website.
CM Map Locations – Visualize and share your locations in a few clicks
cm-map-locations
Display locations on an interactive map with Google Maps. Use as a store locator, showcase business locations, and improve navigation.
PTI Store Locator
pti-store-locator
Display multiple store or branch locations on Google Maps with search, filters, and customizable info windows.
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
WP Store Locator
wp-store-locator
An easy to use location management system that enables users to search for nearby physical stores.
Store Locator for WordPress Posts Developer Profile
1 plugin · 0 total installs
How We Detect Store Locator for WordPress Posts
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-post-store-locator/assets/css/admin-style.css/wp-content/plugins/wp-post-store-locator/assets/js/admin-script.js/wp-content/plugins/wp-post-store-locator/assets/css/aka-front-style.css/wp-content/plugins/wp-post-store-locator/assets/js/aka-maps.js//maps.google.com/maps/api/jshttps://maxcdn.bootstrapcdn.com/font-awesome/4.6.3/css/font-awesome.min.css/wp-content/plugins/wp-post-store-locator/assets/js/admin-script.js?ver=/wp-content/plugins/wp-post-store-locator/assets/js/aka-maps.js?ver=HTML / DOM Fingerprints
slwp-store-locatordata-slwp-settingsslwp_stores/wp-json/wp-post-store-locator/v1/stores[aka-stores]