Geo Controller GPS extension   Security & Risk Analysis

wordpress.org/plugins/cf-geoplugin-gps

Enable GPS lookup for the Geo Controller plugin and collect geodata from mobile visitors.

40 active installs v2.1.4 PHP 7.0+ WP 6.0+ Updated Feb 1, 2026
cf-geoplugingeo-controllergeocodinggeolocationgps
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Geo Controller GPS extension   Safe to Use in 2026?

Generally Safe

Score 100/100

Geo Controller GPS extension   has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The 'cf-geoplugin-gps' v2.1.4 plugin exhibits a mixed security posture. While it demonstrates good practices by avoiding dangerous functions, utilizing prepared statements for all SQL queries, and having no recorded vulnerability history, there are significant concerns regarding its attack surface. The presence of two AJAX handlers without authentication checks presents a clear risk of unauthorized access or execution of plugin functionalities. Although no taint analysis issues were reported, the lack of nonce checks on these unprotected AJAX endpoints further exacerbates the risk, making them susceptible to Cross-Site Request Forgery (CSRF) attacks.

The plugin's static analysis reveals a total of two entry points, both of which are unprotected. This is a critical weakness as it means any unauthenticated user could potentially interact with these handlers. The absence of nonce checks on these AJAX handlers is a particularly concerning oversight, as it directly compromises the integrity and security of these functions. While the plugin has a clean vulnerability history, this does not negate the inherent risks identified in the current code analysis. A balanced conclusion is that the plugin has strengths in its SQL handling and lack of past issues, but its current implementation of AJAX endpoints is a significant security concern.

Key Concerns

  • Unprotected AJAX handlers
  • AJAX handlers without nonce checks
  • Large attack surface without auth
Vulnerabilities
None known

Geo Controller GPS extension   Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Geo Controller GPS extension   Release Timeline

v2.1.4Current
v2.1.3
v2.1.2
v2.1.1
v2.1.0
v2.0.9
v2.0.8
v2.0.7
v2.0.6
v2.0.5
v2.0.4
v2.0.3
v2.0.2
v2.0.1
v2.0.0
v1.1.0
v1.0.10
v1.0.9
v1.0.8
v1.0.7
Code Analysis
Analyzed Mar 16, 2026

Geo Controller GPS extension   Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
18 escaped
Nonce Checks
0
Capability Checks
2
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

75% escaped24 total outputs
Attack Surface
2 unprotected

Geo Controller GPS extension   Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_cf_geoplugin_gps_setinc\classes\GPS.php:31
noprivwp_ajax_cf_geoplugin_gps_setinc\classes\GPS.php:32
WordPress Hooks 26
filtercfgp/settingsinc\classes\GPS.php:19
filtercfgp/settings/defaultinc\classes\GPS.php:20
actionwp_enqueue_scriptsinc\classes\GPS.php:24
actionwp_enqueue_scriptsinc\classes\GPS.php:28
actionwp_footerinc\classes\GPS.php:35
actioncfgp/api/returninc\classes\GPS.php:39
actioncfgp/api/render/responseinc\classes\GPS.php:40
actioncfgp/api/resultsinc\classes\GPS.php:41
actioncfgp/api/default/fieldsinc\classes\GPS.php:42
actiontemplate_redirectinc\classes\GPS.php:44
actioncfgp/options/action/setinc\classes\GPS.php:46
actioncfgp/debug/nav-tab/afterinc\classes\GPS.php:49
actioncfgp/debug/tab-panel/afterinc\classes\GPS.php:50
actionadmin_noticesinc\classes\GPS.php:54
actionadmin_initinc\classes\Requirements.php:42
actionadmin_noticesinc\classes\Requirements.php:54
actionadmin_noticesinc\classes\Requirements.php:82
actionadmin_noticesinc\classes\Requirements.php:92
actionadmin_noticesinc\classes\Requirements.php:101
actionadmin_noticesinc\classes\Requirements.php:119
actionadmin_noticesinc\classes\Requirements.php:135
actionplugins_loadedinc\Init.php:16
actionactivated_plugininc\Init.php:19
actionwp_enqueue_scriptsinc\Init.php:45
filtercfgp/init/include_classesinc\Init.php:80
filtercfgp/init/classesinc\Init.php:85
Maintenance & Trust

Geo Controller GPS extension   Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 1, 2026
PHP min version7.0
Downloads5K

Community Trust

Rating0/100
Number of ratings0
Active installs40
Developer Profile

Geo Controller GPS extension   Developer Profile

Ivijan-Stefan Stipic

7 plugins · 95K total installs

79
trust score
Avg Security Score
100/100
Avg Patch Time
285 days
View full developer profile
Detection Fingerprints

How We Detect Geo Controller GPS extension  

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/cf-geoplugin-gps/inc/classes/js/cf-geoplugin-gps.js
Version Parameters
cf-geoplugin-gps/inc/classes/js/cf-geoplugin-gps.js?ver=

HTML / DOM Fingerprints

CSS Classes
cfgp-gps-google-map-api-key
Data Attributes
id="cfgp-gps-google-map-api-key"
FAQ

Frequently Asked Questions about Geo Controller GPS extension