
Country Flags Info Widget Security & Risk Analysis
wordpress.org/plugins/country-flags-info-widgetEnables a widget in which you can display a list of country with flags, names and misc information.
Is Country Flags Info Widget Safe to Use in 2026?
Generally Safe
Score 100/100Country Flags Info Widget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "country-flags-info-widget" v1.0.0 plugin exhibits a mixed security posture. On one hand, the absence of any recorded vulnerabilities, CVEs, and a low number of entry points with apparent permission checks suggest a relatively stable history and a limited external attack surface. The plugin also demonstrates good practices by utilizing prepared statements for all SQL queries, which significantly mitigates SQL injection risks. However, the static analysis reveals several concerning code signals that point to potential weaknesses. The presence of `create_function` is a significant red flag, as it can be exploited for arbitrary code execution in specific scenarios. Furthermore, a very low percentage of properly escaped output (10%) indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities. The complete lack of nonce checks, capability checks, and unprotected entry points means that if any vulnerabilities were introduced, they could be exploited without significant authentication or authorization hurdles.
Key Concerns
- 10% output properly escaped
- Dangerous function: create_function
- 0 Nonce checks
- 0 Capability checks
Country Flags Info Widget Security Vulnerabilities
Country Flags Info Widget Code Analysis
Dangerous Functions Found
Output Escaping
Country Flags Info Widget Attack Surface
WordPress Hooks 2
Maintenance & Trust
Country Flags Info Widget Maintenance & Trust
Maintenance Signals
Community Trust
Country Flags Info Widget Alternatives
Post Country
post-country
This plug-in allows you to record a country against your posts.
International Telephone Input for Contact Form 7
international-telephone-input-for-contact-form-7
Addon for Contact Form 7 that creates a new type of input for entering and validating international telephone numbers. It adds a flag dropdown, detect …
Country Based Payments for WooCommerce
woocommerce-country-based-payments
Choose which payment gateway will be available in country/countries.
Phone Validator with Flags for WooCommerce
phone-validator-with-flags-for-woocommerce
Adds a country flag and phone validation to the checkout phone field.
Category Country Aware WordPress
category-country-aware
Make both your post content and sidebar category and/or visitor location relevant.
Country Flags Info Widget Developer Profile
3 plugins · 70 total installs
How We Detect Country Flags Info Widget
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/country-flags-info-widget/css/smcfi.css/wp-content/plugins/country-flags-info-widget/css/smcfi.css?ver=HTML / DOM Fingerprints
smcfi-flagsmcfi-namesmcfi-miscsmcfi-instructionshide-if-no-jshide-if-jscountry-flags-infolist-item+5 moresmcfi-action