
Geo Controller GPS extension Security & Risk Analysis
wordpress.org/plugins/cf-geoplugin-gpsEnable GPS lookup for the Geo Controller plugin and collect geodata from mobile visitors.
Is Geo Controller GPS extension Safe to Use in 2026?
Generally Safe
Score 100/100Geo Controller GPS extension has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'cf-geoplugin-gps' v2.1.4 plugin exhibits a mixed security posture. While it demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having no recorded vulnerability history, there are significant concerns regarding its attack surface. The presence of two AJAX handlers without authentication checks presents a clear risk of unauthorized access or execution of plugin functionalities. Although no taint analysis issues were reported, the lack of nonce checks on these unprotected AJAX endpoints further exacerbates the risk, making them susceptible to Cross-Site Request Forgery (CSRF) attacks.
The plugin's static analysis reveals a total of two entry points, both of which are unprotected. This is a critical weakness as it means any unauthenticated user could potentially interact with these handlers. The absence of nonce checks on these AJAX handlers is a particularly concerning oversight, as it directly compromises the integrity and security of these functions. While the plugin has a clean vulnerability history, this does not negate the inherent risks identified in the current code analysis. A balanced conclusion is that the plugin has strengths in its SQL handling and lack of past issues, but its current implementation of AJAX endpoints is a significant security concern.
Key Concerns
- Unprotected AJAX handlers
- AJAX handlers without nonce checks
- Large attack surface without auth
Geo Controller GPS extension Security Vulnerabilities
Geo Controller GPS extension Release Timeline
Geo Controller GPS extension Code Analysis
Output Escaping
Geo Controller GPS extension Attack Surface
AJAX Handlers 2
WordPress Hooks 26
Maintenance & Trust
Geo Controller GPS extension Maintenance & Trust
Maintenance Signals
Community Trust
Geo Controller GPS extension Alternatives
bbPress Topic Location
bbpress-topic-location
This plugin brings topics geolocation to bbPress, and can filter topics by location and radius.
SlimStat Analytics
wp-slimstat
The leading web analytics plugin for WordPress
Geolocation IP Detection
geoip-detect
Provides geographic information detected by an IP adress.
Price Based on Country for WooCommerce
woocommerce-product-price-based-on-countries
Product Pricing and Currency based on Shopper's Country for WooCommerce with multi-currency support and geolocation to boost international sales.
IP Location Block
ip-location-block
Easily block visitors by country, state or ISP provider. Also, protects your site from spam, login attempts, malicious access & more.
Geo Controller GPS extension Developer Profile
7 plugins · 95K total installs
How We Detect Geo Controller GPS extension
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cf-geoplugin-gps/inc/classes/js/cf-geoplugin-gps.jscf-geoplugin-gps/inc/classes/js/cf-geoplugin-gps.js?ver=HTML / DOM Fingerprints
cfgp-gps-google-map-api-keyid="cfgp-gps-google-map-api-key"