
YaMaps for WordPress Plugin Security & Risk Analysis
wordpress.org/plugins/yamapsThe plugin allows you to add Yandex Maps (Яндекс Карты) to pages of your site using a WordPress visual editor.
Is YaMaps for WordPress Plugin Safe to Use in 2026?
Generally Safe
Score 95/100YaMaps for WordPress Plugin has a strong security track record. Known vulnerabilities have been patched promptly.
The "yamaps" plugin v0.6.41 exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices. There are no identified dangerous functions, all SQL queries are properly prepared, and a high percentage (91%) of output is correctly escaped. Furthermore, the plugin includes nonce and capability checks, which are essential for preventing common WordPress attacks. The absence of file operations and external HTTP requests also reduces the attack surface.
However, a significant concern arises from the plugin's vulnerability history, which shows a total of 5 known CVEs, all classified as medium severity and primarily related to Cross-Site Scripting (XSS). Although there are currently no unpatched CVEs for this version, the pattern of past vulnerabilities, particularly XSS, suggests that input sanitization might be an area that requires ongoing vigilance and robust testing. The last recorded vulnerability was in February 2026, which is in the future, indicating a potential data anomaly or that this information is for a future release. The static analysis doesn't reveal any taint flows with unsanitized paths, but the historical XSS issues warrant careful consideration.
In conclusion, while the current code version demonstrates good practices in many areas, the historical prevalence of XSS vulnerabilities is a notable weakness. Users should ensure they are always running the latest patched version of this plugin and be aware of the potential for similar issues to arise if input handling is not consistently strict. The plugin's limited attack surface and good static analysis results provide a solid foundation, but the historical context demands attention.
Key Concerns
- Historical medium severity XSS vulnerabilities
YaMaps for WordPress Plugin Security Vulnerabilities
CVEs by Year
Severity Breakdown
5 total CVEs
YaMaps for WordPress <= 0.6.40 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Parameters
YaMaps <= 0.6.39 - Authenticated (Contributor+) Stored Cross-Site Scripting
YaMaps for WordPress <= 0.6.40 - Authenticated (Contributor+) Stored Cross-Site Scripting
YaMaps for WordPress <= 0.6.28 - Authenticated (Contributor+) Stored Cross-Site Scripting
YaMaps <= 0.6.25 - Authenticaterd (Contributor+) Stored Cross-Site Scripting via Shortcode
YaMaps for WordPress Plugin Code Analysis
Output Escaping
YaMaps for WordPress Plugin Attack Surface
Shortcodes 2
WordPress Hooks 8
Maintenance & Trust
YaMaps for WordPress Plugin Maintenance & Trust
Maintenance Signals
Community Trust
YaMaps for WordPress Plugin Alternatives
Yandex.Metrica
wp-yandex-metrika
The free official Yandex.Metrica plugin for WordPress.
Maps from Yandex for Elementor
mihdan-elementor-yandex-maps
Yandex Maps widget for Elementor
WT Yandex Metrika
wt-yandex-metrika
Простое добавление на сайт счетчика Яндекс.Метрика
Captcha by Yandex for Contact Form 7
captcha-by-yandex-for-contact-form-7
Add antispam Yandex SmartCaptcha for your forms with Contact Form 7
Simple Counter
abwp-simple-counter
The installation of the counter of Yandex.Metrics and Google Analytics on the website without editing the files of the selected theme.
YaMaps for WordPress Plugin Developer Profile
2 plugins · 10K total installs
How We Detect YaMaps for WordPress Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/yamaps/js/btn.js/wp-content/plugins/yamaps/js/shortcode_parser.js/wp-content/plugins/yamaps/templates/tmpl-editor-yamap.htmlhttps://api-maps.yandex.ru/2.1/js/shortcode_parser.js?v=js/btn.js?v=HTML / DOM Fingerprints
yamapsdata-yamap-optionsyamap_objectyamap_defaults[yamap