
WP Store Locator Security & Risk Analysis
wordpress.org/plugins/wp-store-locatorAn easy to use location management system that enables users to search for nearby physical stores.
Is WP Store Locator Safe to Use in 2026?
Generally Safe
Score 96/100WP Store Locator has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The wp-store-locator plugin v2.3.0 presents a mixed security posture. On the positive side, a high percentage of SQL queries use prepared statements and output escaping is well-implemented, indicating good development practices for core functionalities. The absence of critical or high severity taint analysis findings and the lack of bundled libraries are also encouraging signs. However, the plugin has a notable attack surface with 11 entry points, of which 3 are AJAX handlers lacking authentication checks. This is a significant concern as it allows unauthenticated users to interact with potentially sensitive parts of the plugin. Furthermore, the plugin has a history of a high severity "Deserialization of Untrusted Data" vulnerability, even though it is currently patched. This historical pattern suggests a potential area of weakness that attackers might target again if not rigorously reviewed.
Overall, while the plugin demonstrates good practices in data handling and output sanitization, the presence of unprotected AJAX endpoints and the historical vulnerability in deserialization are key risks that require attention. The attack surface could be further hardened by implementing proper authentication and capability checks on all entry points.
Key Concerns
- Unprotected AJAX handlers
- High severity vulnerability in history
- SQL queries not always prepared
WP Store Locator Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
WP Store Locator <= 2.2.261 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'wpsl_address' Post Meta
Store Locator <= 2.2.260 - Authenticated (Contributor+) PHP Object Injection
WP Store Locator Release Timeline
WP Store Locator Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WP Store Locator Attack Surface
AJAX Handlers 6
REST API Routes 1
Shortcodes 4
WordPress Hooks 61
Maintenance & Trust
WP Store Locator Maintenance & Trust
Maintenance Signals
Community Trust
WP Store Locator Alternatives
Store Locator WordPress
agile-store-locator
Agile Store Locator is a premium store finder plugin designed to offer you immediate access to all the best stores in your local area.
Store Locator for WordPress📍
storelocator
Create a store locator for your website in minutes. Add all the store locations in google sheets and embed map on your website.
Store Locator
ascsoftw-store-locator
Ascsoftw Store Locator is a powerful plugin which lets your users Search the Nearest Stores and display them in highly customized Google Maps.
PTI Store Locator
pti-store-locator
Display multiple store or branch locations on Google Maps with search, filters, and customizable info windows.
WP Maps – Store Locator,Google Maps,OpenStreetMap,Mapbox,Listing,Directory & Filters
wp-google-map-plugin
WordPress map plugin for Google Maps, OpenStreetMap & Mapbox with store locator, filterable listings & custom markers.
WP Store Locator Developer Profile
1 plugin · 50K total installs
How We Detect WP Store Locator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wp-store-locator/css/wpsl-frontend.css/wp-content/plugins/wp-store-locator/css/wpsl-admin.css/wp-content/plugins/wp-store-locator/js/wpsl-admin.js/wp-content/plugins/wp-store-locator/js/wpsl-frontend.js/wp-content/plugins/wp-store-locator/js/wpsl-map.js/wp-content/plugins/wp-store-locator/js/wpsl-shortcode-generator.js/wp-content/plugins/wp-store-locator/js/wpsl-frontend.js/wp-content/plugins/wp-store-locator/js/wpsl-map.js/wp-content/plugins/wp-store-locator/css/wpsl-frontend.css?ver=/wp-content/plugins/wp-store-locator/css/wpsl-admin.css?ver=/wp-content/plugins/wp-store-locator/js/wpsl-admin.js?ver=/wp-content/plugins/wp-store-locator/js/wpsl-frontend.js?ver=/wp-content/plugins/wp-store-locator/js/wpsl-map.js?ver=/wp-content/plugins/wp-store-locator/js/wpsl-shortcode-generator.js?ver=HTML / DOM Fingerprints
wpsl-store-locatorwpsl-location-search-wrapwpsl-search-wrapwpsl-search-inputwpsl-search-buttonwpsl-stores-wrapwpsl-store-singlewpsl-store-name+19 more<!-- WP Store LocatorWP Store LocatorCopyright (C) 2013 Tijmen Smit - tijmen@wpstorelocator.coThis program is free software: you can redistribute it and/or modify+33 moredata-wpsl-map-iddata-wpsl-marker-iddata-wpsl-latdata-wpsl-lngdata-wpsl-zoomdata-wpsl-map-type+6 morewpsl_map_optionswpsl_map_markerswpsl_settingswpsl_i18n_stringsWPSLAdmin/wp-json/wpsl/v1/stores/wp-json/wpsl/v1/store/wp-json/wpsl/v1/settings[wpsl][wpsl_search][wpsl_results][wpsl_map]