
Admin Country Allowlist Security & Risk Analysis
wordpress.org/plugins/admin-country-allowlistBy far the simplest country allowlist plugin available. Locks admin panel and XMLRPC access to a given list of allowed countries.
Is Admin Country Allowlist Safe to Use in 2026?
Generally Safe
Score 100/100Admin Country Allowlist has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'admin-country-allowlist' plugin, version 1.4.0, appears to have a generally good security posture based on the static analysis. The absence of detected dangerous functions, a lack of raw SQL queries, and a reasonable percentage of properly escaped output are positive indicators. Furthermore, the plugin has no recorded vulnerabilities, which suggests a history of secure development or timely patching.
However, there are a few areas that warrant attention. The plugin utilizes file operations, making it crucial to ensure these operations are not susceptible to path traversal or other file manipulation vulnerabilities, although no taint flows were identified. The presence of one external HTTP request also introduces a potential vector for supply chain attacks or unintended data exposure if not handled securely. The plugin also has a single cron event, which should be verified to ensure it does not introduce any security risks. The total lack of nonce checks across all entry points is a significant concern, as it leaves any potential future additions to the attack surface vulnerable to CSRF attacks.
In conclusion, while the plugin shows strengths in areas like SQL handling and output escaping, the absence of nonce checks on all potential entry points and the presence of file operations and external HTTP requests represent areas for improvement. The clean vulnerability history is encouraging, but the static analysis findings highlight the need for continued vigilance, particularly regarding input validation and access control on all code paths.
Key Concerns
- Missing nonce checks on all entry points
- Potential risk from file operations
- Potential risk from external HTTP requests
- One cron event requires review
Admin Country Allowlist Security Vulnerabilities
Admin Country Allowlist Code Analysis
Output Escaping
Admin Country Allowlist Attack Surface
WordPress Hooks 9
Scheduled Events 1
Maintenance & Trust
Admin Country Allowlist Maintenance & Trust
Maintenance Signals
Community Trust
Admin Country Allowlist Alternatives
iQ Block Country
iq-block-country
Allow or disallow visitors from certain countries accessing (parts of) your website
WP fail2ban Blocklist
wpf2b-addon-blocklist
WP fail2ban Blocklist is a collaborative preemptive blocklist for WordPress.
Banhammer – Monitor Site Traffic, Block Bad Users and Bots
banhammer
Monitor traffic and ban unwanted visitors. Block any user or IP address so they can't access your site.
Country Block – Ultimate Geo-Blocker, IP Ban & Login Security
vpndeals-country-block
🚀 INSTANT, 100% FREE & PRECISE: The Essential Geo Blocker! Ban, block, or restrict countries with Guaranteed accuracy via Daily MaxMind Updates.
bad_ip WP
bad-ip-wp
Lightweight WordPress firewall plugin to block malicious IPs, TOR nodes, and brute-force attacks with real-time sync and control.
Admin Country Allowlist Developer Profile
1 plugin · 80 total installs
How We Detect Admin Country Allowlist
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.