
country-redirect Security & Risk Analysis
wordpress.org/plugins/country-redirectSimple to use free WordPress plugin for redirection depending visitor's country
Is country-redirect Safe to Use in 2026?
Generally Safe
Score 85/100country-redirect has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "country-redirect" plugin v1.3.3 exhibits a generally good security posture regarding its attack surface, with zero identified entry points like AJAX handlers, REST API routes, or shortcodes. This significantly limits direct avenues for external attacks. However, the code analysis reveals notable areas of concern. A significant portion of SQL queries are not using prepared statements, which is a critical vulnerability that can lead to SQL injection if the data is not properly sanitized before being used in the query. Furthermore, only 23% of output is properly escaped, indicating a risk of Cross-Site Scripting (XSS) vulnerabilities where untrusted data could be injected into the page content. The taint analysis also identified one flow with an unsanitized path, which could potentially lead to unintended file access or manipulation, though it was not classified as critical or high severity. The plugin's history of zero recorded CVEs is a positive indicator, suggesting a generally stable and well-maintained codebase. However, this should not be taken as a guarantee of future security, especially given the identified coding practices that introduce inherent risks.
In conclusion, while the plugin has a minimal attack surface and no known vulnerabilities in its history, the static analysis highlights specific, high-impact coding weaknesses. The lack of prepared statements in SQL queries and the low rate of output escaping represent tangible risks that should be addressed. The single unsanitized path in the taint analysis, while not critically severe, also warrants attention. Users should be aware that these identified weaknesses could be exploited, despite the absence of past CVEs.
Key Concerns
- Raw SQL queries without prepared statements
- Low rate of output escaping
- Flow with unsanitized path (taint analysis)
country-redirect Security Vulnerabilities
country-redirect Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
country-redirect Attack Surface
WordPress Hooks 5
Maintenance & Trust
country-redirect Maintenance & Trust
Maintenance Signals
Community Trust
country-redirect Alternatives
Geo Redirect
geo-targetly-geo-redirect
Redirect visitors based on geolocation (country, state, city, lat/lng/radius)
Redirect Modal Based On Country
redirect-modal-based-on-country
Let your visitors know that your website is also available specifically for their country
Geo Redirects Lite
geo-redirects
Create Geo redirects in an incredible easy way and use different set of rules to match users
IP2Location Country Blocker
ip2location-country-blocker
Blocks unwanted visitors from accessing your frontend (blog pages) or backend (admin area) by countries or proxy servers.
IP Location Block
ip-location-block
Easily block visitors by country, state or ISP provider. Also, protects your site from spam, login attempts, malicious access & more.
country-redirect Developer Profile
1 plugin · 400 total installs
How We Detect country-redirect
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/country-redirect/css/style.css/wp-content/plugins/country-redirect/js/redirect.js/wp-content/plugins/country-redirect/js/redirect.jscountry-redirect/style.css?ver=country-redirect/js/redirect.js?ver=HTML / DOM Fingerprints
cntrd_settings_wrap<!-- Country Redirect Settings --><!-- Country Redirect Engine Settings --><!-- Country Redirect Redirect Settings --><!-- Country Redirect Whitelist Settings -->data-cntrd-redirect-urlswindow.cntrd_redirect_urlsvar cntrd_redirect_urls