YaMaps for WordPress Plugin Security & Risk Analysis

wordpress.org/plugins/yamaps

The plugin allows you to add Yandex Maps (Яндекс Карты) to pages of your site using a WordPress visual editor.

10K active installs v0.6.41 PHP + WP 4.7+ Updated Jan 15, 2026
%d1%8f%d0%bd%d0%b4%d0%b5%d0%ba%d1%81%d0%ba%d0%b0%d1%80%d1%82%d0%b0%d0%ba%d0%b0%d1%80%d1%82%d1%8bmapsyandex
95
A · Safe
CVEs total5
Unpatched0
Last CVEFeb 18, 2026
Safety Verdict

Is YaMaps for WordPress Plugin Safe to Use in 2026?

Generally Safe

Score 95/100

YaMaps for WordPress Plugin has a strong security track record. Known vulnerabilities have been patched promptly.

5 known CVEsLast CVE: Feb 18, 2026Updated 2mo ago
Risk Assessment

The "yamaps" plugin v0.6.41 exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to secure coding practices. There are no identified dangerous functions, all SQL queries are properly prepared, and a high percentage (91%) of output is correctly escaped. Furthermore, the plugin includes nonce and capability checks, which are essential for preventing common WordPress attacks. The absence of file operations and external HTTP requests also reduces the attack surface.

However, a significant concern arises from the plugin's vulnerability history, which shows a total of 5 known CVEs, all classified as medium severity and primarily related to Cross-Site Scripting (XSS). Although there are currently no unpatched CVEs for this version, the pattern of past vulnerabilities, particularly XSS, suggests that input sanitization might be an area that requires ongoing vigilance and robust testing. The last recorded vulnerability was in February 2026, which is in the future, indicating a potential data anomaly or that this information is for a future release. The static analysis doesn't reveal any taint flows with unsanitized paths, but the historical XSS issues warrant careful consideration.

In conclusion, while the current code version demonstrates good practices in many areas, the historical prevalence of XSS vulnerabilities is a notable weakness. Users should ensure they are always running the latest patched version of this plugin and be aware of the potential for similar issues to arise if input handling is not consistently strict. The plugin's limited attack surface and good static analysis results provide a solid foundation, but the historical context demands attention.

Key Concerns

  • Historical medium severity XSS vulnerabilities
Vulnerabilities
5

YaMaps for WordPress Plugin Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2024
2024
2 CVEs in 2025
2025
1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
5

5 total CVEs

CVE-2025-14851medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

YaMaps for WordPress <= 0.6.40 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Parameters

Feb 18, 2026 Patched in 0.6.41 (1d)
CVE-2025-13958medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

YaMaps <= 0.6.39 - Authenticated (Contributor+) Stored Cross-Site Scripting

Dec 8, 2025 Patched in 0.6.40 (30d)
CVE-2025-32172medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

YaMaps for WordPress <= 0.6.40 - Authenticated (Contributor+) Stored Cross-Site Scripting

Apr 4, 2025 Patched in 0.6.41 (291d)
CVE-2024-43224medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

YaMaps for WordPress <= 0.6.28 - Authenticated (Contributor+) Stored Cross-Site Scripting

Aug 9, 2024 Patched in 0.6.30 (187d)
CVE-2023-0270medium · 6.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

YaMaps <= 0.6.25 - Authenticaterd (Contributor+) Stored Cross-Site Scripting via Shortcode

Jan 17, 2023 Patched in 0.6.26 (645d)
Code Analysis
Analyzed Mar 16, 2026

YaMaps for WordPress Plugin Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
8
80 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

91% escaped88 total outputs
Attack Surface

YaMaps for WordPress Plugin Attack Surface

Entry Points2
Unprotected0

Shortcodes 2

[yaplacemark] includes\shortcodes.php:373
[yamap] includes\shortcodes.php:374
WordPress Hooks 8
filtermce_external_pluginsincludes\admin.php:85
filtermce_buttonsincludes\admin.php:86
actionadmin_headincludes\admin.php:87
actionadmin_headincludes\admin.php:88
actionwp_enqueue_scriptsincludes\api.php:59
actionadmin_menuoptions.php:23
actionadmin_initoptions.php:335
actionplugins_loadedyamap.php:30
Maintenance & Trust

YaMaps for WordPress Plugin Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJan 15, 2026
PHP min version
Downloads158K

Community Trust

Rating94/100
Number of ratings41
Active installs10K
Developer Profile

YaMaps for WordPress Plugin Developer Profile

Yuri Baranov

2 plugins · 10K total installs

72
trust score
Avg Security Score
90/100
Avg Patch Time
231 days
View full developer profile
Detection Fingerprints

How We Detect YaMaps for WordPress Plugin

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/yamaps/js/btn.js/wp-content/plugins/yamaps/js/shortcode_parser.js/wp-content/plugins/yamaps/templates/tmpl-editor-yamap.html
Script Paths
https://api-maps.yandex.ru/2.1/
Version Parameters
js/shortcode_parser.js?v=js/btn.js?v=

HTML / DOM Fingerprints

CSS Classes
yamaps
Data Attributes
data-yamap-options
JS Globals
yamap_objectyamap_defaults
Shortcode Output
[yamap
FAQ

Frequently Asked Questions about YaMaps for WordPress Plugin