[凹凸曼]显示IP归属地 Security & Risk Analysis

wordpress.org/plugins/apoyl-ip

实现发布文章记录IP地址,用户发布文章显示IP归属地,评论显示IP归属地,更加方便了解用户来自哪里.

10 active installs v1.6.0 PHP 7.4+ WP 6.0+ Updated Apr 24, 2025
geolocationipip-address%e5%9c%b0%e7%90%86%e4%bd%8d%e7%bd%ae%e5%bd%92%e5%b1%9e%e5%9c%b0
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is [凹凸曼]显示IP归属地 Safe to Use in 2026?

Generally Safe

Score 92/100

[凹凸曼]显示IP归属地 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "apoyl-ip" plugin v1.6.0 exhibits a generally strong security posture, primarily due to its minimal attack surface and the absence of known vulnerabilities. The static analysis reveals no AJAX handlers, REST API routes, shortcodes, or cron events, significantly reducing the potential entry points for attackers. This is a positive indicator of secure coding practices. Furthermore, the taint analysis shows no high or critical severity flows, and there are no recorded CVEs, suggesting a mature and stable codebase. The presence of a nonce check is also a good sign. However, there are a couple of areas for improvement. The plugin uses raw SQL queries without prepared statements, which, while not immediately exploitable in this context due to the lack of entry points, represents a potential risk if new entry points are added or existing ones are modified. Additionally, while most output is properly escaped, 15% is not, which could lead to cross-site scripting (XSS) vulnerabilities in specific scenarios. Overall, "apoyl-ip" v1.6.0 appears to be a secure plugin with a low risk profile, but addressing the raw SQL queries and ensuring 100% output escaping would further solidify its security.

Key Concerns

  • Raw SQL queries without prepared statements
  • Unescaped output (15% of total)
Vulnerabilities
None known

[凹凸曼]显示IP归属地 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

[凹凸曼]显示IP归属地 Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

[凹凸曼]显示IP归属地 Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
0 prepared
Unescaped Output
3
17 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared3 total queries

Output Escaping

85% escaped20 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<setting> (admin\partials\setting.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

[凹凸曼]显示IP归属地 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
actionplugins_loadedincludes\ip.php:46
actionadmin_menuincludes\ip.php:52
actionsave_postincludes\ip.php:53
actionwp_enqueue_scriptsincludes\ip.php:64
actionthe_authorincludes\ip.php:65
actionget_comment_authorincludes\ip.php:66
Maintenance & Trust

[凹凸曼]显示IP归属地 Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedApr 24, 2025
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

[凹凸曼]显示IP归属地 Developer Profile

apoyl

29 plugins · 740 total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect [凹凸曼]显示IP归属地

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/apoyl-ip/admin/css/admin.css/wp-content/plugins/apoyl-ip/admin/js/admin.js/wp-content/plugins/apoyl-ip/public/css/public.css
Version Parameters
apoyl-ip/admin/css/admin.css?ver=apoyl-ip/admin/js/admin.js?ver=apoyl-ip/public/css/public.css?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about [凹凸曼]显示IP归属地