
Content for your Country Security & Risk Analysis
wordpress.org/plugins/content-for-your-countryShows the desired content only for the desired country. Widget also included.
Is Content for your Country Safe to Use in 2026?
Generally Safe
Score 85/100Content for your Country has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "content-for-your-country" v1.1 plugin exhibits a mixed security posture. While it has a small attack surface with only one entry point (a shortcode) and no known vulnerabilities or CVEs historically, the static analysis reveals significant concerns regarding output escaping and data sanitization. Notably, 0% of its 13 outputs are properly escaped, which is a critical security flaw that could lead to cross-site scripting (XSS) vulnerabilities. Furthermore, the taint analysis identified one flow with unsanitized paths classified as high severity, indicating a potential risk of unintended data manipulation or exposure.
The plugin's lack of nonce checks and capability checks on its single entry point is also a weakness, as it doesn't implement standard WordPress security mechanisms to prevent unauthorized actions or data access. The presence of file operations and 75% of SQL queries not using prepared statements, while not immediately critical given the limited attack surface and no known vulnerabilities, still present potential areas for exploitation if an attacker can influence the data used in these operations.
In conclusion, the plugin's strength lies in its minimal known history of vulnerabilities and small attack surface. However, the critical lack of output escaping and the high-severity taint flow are significant weaknesses that expose the site to potential XSS and other data-related attacks. Addressing these issues should be a priority to improve the plugin's overall security.
Key Concerns
- 0% of outputs properly escaped
- High severity taint flow with unsanitized paths
- No nonce checks
- No capability checks
- 2 file operations
- 25% of SQL queries not using prepared statements
Content for your Country Security Vulnerabilities
Content for your Country Release Timeline
Content for your Country Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Content for your Country Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
Content for your Country Maintenance & Trust
Maintenance Signals
Community Trust
Content for your Country Alternatives
Site Kit by Google – Analytics, Search Console, AdSense, Speed
google-site-kit
Site Kit is a one-stop solution for WordPress users to use everything Google has to offer to make them successful on the web.
Google for WooCommerce
google-listings-and-ads
Native integration with Google that allows merchants to easily display their products across Google’s network.
GTM4WP – A Google Tag Manager (GTM) plugin for WordPress
duracelltomi-google-tag-manager
Advanced tag management for WordPress with Google Tag Manager
TablePress – Tables in WordPress made easy
tablepress
Embed beautiful, accessible, and interactive tables into your WordPress website’s posts and pages, without having to write code!
Meta pixel for WordPress
official-facebook-pixel
Grow your business with Meta for WordPress!
Content for your Country Developer Profile
1 plugin · 10 total installs
How We Detect Content for your Country
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/content-for-your-country/css/style.css/wp-content/plugins/content-for-your-country/js/scripts.js/wp-content/plugins/content-for-your-country/js/scripts.jscontent-for-your-country/style.css?ver=content-for-your-country/scripts.js?ver=HTML / DOM Fingerprints
cbcid="cbc-widget"class="widefat"[privatecontent][/privatecontent]