
Country Access Blocker Security & Risk Analysis
wordpress.org/plugins/country-access-blockerBlock or allow website visitors from specific countries based on IP geolocation.
Is Country Access Blocker Safe to Use in 2026?
Generally Safe
Score 100/100Country Access Blocker has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The country-access-blocker plugin version 1.6 exhibits a generally good security posture based on the static analysis and vulnerability history provided. The complete absence of known CVEs and a lack of critical or high severity issues in its history are positive indicators. Furthermore, the code signals show a healthy approach to database interaction, with 100% of SQL queries using prepared statements and no dangerous functions or file operations detected. The plugin also correctly implements a nonce check, which is a fundamental security measure.
However, there are areas of concern that warrant attention. The most significant is the output escaping, where only 43% of outputs are properly escaped. This suggests a potential for cross-site scripting (XSS) vulnerabilities if user-supplied data is directly reflected in the output without sufficient sanitization. Additionally, the taint analysis revealed two flows with unsanitized paths, which, while not classified as critical or high severity in this analysis, represent potential pathways for malicious input to reach sensitive functions. The presence of one external HTTP request also introduces a dependency that could be exploited if the external resource is compromised.
In conclusion, while the plugin has strengths in its database security and lack of historical vulnerabilities, the weaknesses in output escaping and the identified unsanitized paths in the taint analysis present tangible risks. These issues should be prioritized for remediation to further strengthen the plugin's security.
Key Concerns
- Low output escaping percentage
- Taint flow with unsanitized paths
- External HTTP request
Country Access Blocker Security Vulnerabilities
Country Access Blocker Release Timeline
Country Access Blocker Code Analysis
Output Escaping
Data Flow Analysis
Country Access Blocker Attack Surface
WordPress Hooks 3
Maintenance & Trust
Country Access Blocker Maintenance & Trust
Maintenance Signals
Community Trust
Country Access Blocker Alternatives
Login IP & Country Restriction
login-ip-country-restriction
Tighten your website security and fight against dictionary bot attacks originating from other countries, by denying access.
Geo Blocker – Control Site Access by Region and IP
geo-blocker
🔐 Block or allow visitors by country. Track access attempts. View analytics. Stay in control — effortlessly.
IP & Country Blocker Lite
ip-blocker-lite
Advanced WordPress security plugin with IP/country blocking and two-factor authentication for comprehensive website protection.
Country Blocker and Geoblocker FREE
block-website-access-by-region-lite
Block visitors by country in one click. Geo blocker with VPN detection, IP blocking & country restrictions. GDPR & CCPA compliance made easy.
Block Country
block-country
Set country and IP to block your website. You can also set IP address to unblock for any special IP Address.
Country Access Blocker Developer Profile
2 plugins · 640 total installs
How We Detect Country Access Blocker
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/country-access-blocker/assets/css/admin.css/wp-content/plugins/country-access-blocker/assets/js/admin.jsassets/js/admin.jscountry-access-blocker/assets/css/admin.css?ver=country-access-blocker/assets/js/admin.js?ver=HTML / DOM Fingerprints
cab-pagecab-enabledcab-disabledcab-enable-gatecab-enable-cardcab-enable-titlecab-enable-subcab-enable-toggle+11 moredata-minedata-just-enableddata-dismiss-key