
Category Country Aware WordPress Security & Risk Analysis
wordpress.org/plugins/category-country-awareMake both your post content and sidebar category and/or visitor location relevant.
Is Category Country Aware WordPress Safe to Use in 2026?
Generally Safe
Score 85/100Category Country Aware WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the 'category-country-aware' v1.2.3 plugin presents a mixed picture. On the positive side, the plugin demonstrates a good practice by exclusively using prepared statements for its SQL queries, significantly reducing the risk of SQL injection vulnerabilities. The absence of any known vulnerabilities in its history is also a strong indicator of previous diligent security efforts. However, several areas raise concerns. The presence of two AJAX handlers without authentication checks creates a significant attack surface, as these entry points could be exploited by unauthenticated users to execute unintended actions. Furthermore, a concerning 85% of output is not properly escaped, leaving the plugin vulnerable to cross-site scripting (XSS) attacks. The use of the `create_function` dangerous function, though only one instance, is a known security risk that should be avoided. Finally, the taint analysis indicates flows with unsanitized paths, suggesting a potential for improper data handling, even if no critical or high severity issues were identified in this specific analysis.
Key Concerns
- Unprotected AJAX handlers
- High percentage of unescaped output
- Use of dangerous function create_function
- Flows with unsanitized paths
Category Country Aware WordPress Security Vulnerabilities
Category Country Aware WordPress Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Category Country Aware WordPress Attack Surface
AJAX Handlers 2
Shortcodes 9
WordPress Hooks 18
Maintenance & Trust
Category Country Aware WordPress Maintenance & Trust
Maintenance Signals
Community Trust
Category Country Aware WordPress Alternatives
Iks Menu – WordPress Category Accordion Menu & FAQs
iks-menu
Super customizable WordPress plugin for displaying custom menus, taxonomy/category terms and FAQs as accordion menu (with images support).
WP Categories Widget
wp-categories-widget
Display the list of categories for any taxonomies type (WooCommerce Product Category, Blog Category, Project Category...etc) in sidebar
Advanced Categories Widget
advanced-categories-widget
A highly customizable categories widget for WordPress with thumbnails and descriptions.
Geolocation Detector for Gravity Forms
geolocation-detector-for-gravity-forms
Provides a dynamic country detection for Gravity Forms . Requires GeoIP Detect Plugin.
Country Caching For WP Super Cache
country-caching-extension-for-wp-super-cache
Extends WP Super Cache to cache by page/visitor country instead of just page. Solves "wrong country content" Geo-Location issues.
Category Country Aware WordPress Developer Profile
3 plugins · 410 total installs
How We Detect Category Country Aware WordPress
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/category-country-aware/css/cca-textwidget.css/wp-content/plugins/category-country-aware/js/cca-textwidget.js/wp-content/plugins/category-country-aware/js/cca-textwidget.jscategory-country-aware/style.css?ver=category-country-aware/cca-textwidget.css?ver=category-country-aware/cca-textwidget.js?ver=HTML / DOM Fingerprints
cca-highlight outside of classes; constants and functions for "internal" use are prefixed "CCA_" for widget and "CCAX_" for extension/dashboard stuff CSS classes and user/developer filters/actions/shortcodes are prefixed "cca_" or "cca-" for CSS for update testing - uncomment in previous (i.e. currently installed) file do not uncomment in repository make ready for language files+4 moredata-cca-country-codewindow.CCAgeoip