WPIntell

Source evidence

Google Maps security notification

MapPress Maps for WordPress · support · 2024-06-29T16:34:00+00:00

mixedsentiment
highseverity
0.94relevance
3replies
Evidence linked to opportunitycommercial context

Proof Health

Open evidence

Commercial opportunities need traceable source links before they are treated as build-worthy.

5 / 34 rows with source links

14.7% of this page's analysis has direct source links.

0 build-decision rows missing links

0 rows here require auditable proof before promotion.

29 rows with no attached evidence

0 rows have source counts but still need direct links.

Conversation

support
bdd resolved
Received a Google Maps security notification yesterday titled “[Security Alert]: Polyfill.io Issue for Google Maps Platform users” — is that a concern for this plugin? Here’s what it said: We have become aware of a security issue that may be affecting websites using specific third-party libraries (including polyfill.io). This issue can sometimes redirect visitors away from the intended website without website owner knowledge or permission, or potentially cause other malicious behavior. Many of the Maps JavaScript API samples in the Developer Documentation previously included a polyfill.io script declaration. We have removed this from those samples. If you have used the Maps JavaScript API samples that contain this declaration, we recommend removing the declaration. Investigate your website: Check your website’s code to see if you’re loading any compromised libraries (including polyfill.io). Remove or replace the code: If you find compromised libraries, consider: Hosting a clean, secure version of the code yourself Switching to an alternative library or provider Removing the library if you don’t need it Re-deploy your code through your regular process. The Google Maps Platform Team Thanks. HI, Good question – but I don’t think it’s a concern. The infected code was on Google’s web sites with map examples. MapPress doesn’t use any polyfills, and neither does the Maps API. Thanks for the reply. At the bottom of the notification message, they’d said: For your reference, attached is a list of your projects where we have detected Maps Javascript API usage. Please check all sites associated with these projects. And the attachment listed the site where I use MapPress, so I wanted to check in to be sure. Guess they were concerned about third-party usage in the past that might’ve used polyfills? Either way, sounds like we’re okay on this. 🙂 Thanks. polyfill is core in wordpress, I think this error is a mistake by Google.

Comments

3 shown
chrisvrichardson 2024-06-29T22:00:00+00:00

HI, Good question – but I don’t think it’s a concern. The infected code was on Google’s web sites with map examples. MapPress doesn’t use any polyfills, and neither does the Maps API.

bdd 2024-06-29T22:09:00+00:00

Thanks for the reply. At the bottom of the notification message, they’d said: For your reference, attached is a list of your projects where we have detected Maps Javascript API usage. Please check all sites associated with these projects. And the attachment listed the site where I use MapPress, so I wanted to check in to be sure. Guess they were concerned about third-party usage in the past that might’ve used polyfills? Either way, sounds like we’re okay on this. 🙂 Thanks.

technicalx 2024-06-30T23:45:00+00:00

polyfill is core in wordpress, I think this error is a mistake by Google.