
Block Country Security & Risk Analysis
wordpress.org/plugins/block-countrySet country and IP to block your website. You can also set IP address to unblock for any special IP Address.
Is Block Country Safe to Use in 2026?
Use With Caution
Score 63/100Block Country has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The 'block-country' plugin v1.0 exhibits a mixed security posture. On the positive side, it demonstrates good practices by exclusively using prepared statements for its SQL queries and making no external HTTP requests. Furthermore, the static analysis reveals no dangerous functions, zero shortcodes, cron events, or obvious attack surface in terms of AJAX handlers or REST API routes. This suggests a conscious effort to avoid common entry points for attacks.
However, significant concerns arise from the output escaping and taint analysis. A concerning 0% of output is properly escaped, indicating a high risk of Cross-Site Scripting (XSS) vulnerabilities where user-supplied data, if processed by the plugin, could be rendered unsafely in the browser. The taint analysis reveals three flows with unsanitized paths, all of which, while not classified as critical or high severity in this scan, represent potential vectors for data manipulation or unauthorized actions if an attacker can inject malicious input.
The vulnerability history also presents a substantial risk. The presence of one currently unpatched medium-severity CVE, identified as Cross-Site Request Forgery (CSRF), is a direct indicator of a known, exploitable flaw. The pattern of past vulnerabilities, though not detailed here, coupled with the unpatched CVE, suggests a recurring need for diligent security patching and code review within this plugin. While the plugin avoids many common pitfalls, the unaddressed CVE and lack of output sanitization are critical weaknesses that demand immediate attention.
Key Concerns
- Currently unpatched medium CVE
- 0% of output properly escaped
- 3 unsanitized paths found in taint analysis
- Missing nonce checks
- Missing capability checks
Block Country Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Block Country <= 1.0 - Cross-Site Request Forgery
Block Country Release Timeline
Block Country Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Block Country Attack Surface
WordPress Hooks 2
Maintenance & Trust
Block Country Maintenance & Trust
Maintenance Signals
Community Trust
Block Country Alternatives
IP2Location Country Blocker
ip2location-country-blocker
Blocks unwanted visitors from accessing your frontend (blog pages) or backend (admin area) by countries or proxy servers.
Login IP & Country Restriction
login-ip-country-restriction
Tighten your website security and fight against dictionary bot attacks originating from other countries, by denying access.
Country Access Blocker
country-access-blocker
Block or allow website visitors from specific countries based on IP geolocation.
Restrict Country Access
restrict-country-access
Sometimes we need to block access of WordPress site in some Country.
Block IP Address for WooCommerce
block-ip-address-for-woocommerce
Block IP Address for WooCommerce – Easily block IP address from accessing your WooCommerce shop, homepage, or specific product categories and redirect …
Block Country Developer Profile
5 plugins · 110 total installs
How We Detect Block Country
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/block-country/block-country.css/wp-content/plugins/block-country/js/block-country.jsblock-country/style.css?ver=block-country.js?ver=