Feed GeoMashup Security & Risk Analysis

wordpress.org/plugins/feed-geomashup

Let two great plugins play great together. Use FeedWordPress to aggregate geodata generated by GeoMashup.

10 active installs v2.2.1 PHP + WP 2.8+ Updated Apr 23, 2015
feedwordpressgeodatageomashupgeorsssyndication
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Feed GeoMashup Safe to Use in 2026?

Generally Safe

Score 85/100

Feed GeoMashup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

The static analysis of feed-geomashup v2.2.1 indicates a generally good security posture, with no immediately apparent critical vulnerabilities like dangerous functions, unescaped output, or raw SQL queries. The plugin also boasts no known CVEs, which is a positive indicator of past security diligence or a lack of exploitation. The absence of shortcodes, cron events, and a limited attack surface further contribute to its security. However, a significant concern arises from the taint analysis, which identified two flows with unsanitized paths. While these did not reach critical or high severity in the analysis, unsanitized paths are inherently risky as they can lead to unexpected behavior or vulnerabilities if input is not handled correctly, especially when interacting with file systems or external resources. The complete lack of nonce checks, capability checks, and AJAX/REST API handlers (even if none are present) suggests a potential for future issues if functionality is added without proper security controls. The plugin appears to have no recorded vulnerability history, which is positive, but it also means there's less data to assess its long-term security track record.

Key Concerns

  • Unsanitized paths found in taint analysis
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Feed GeoMashup Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Feed GeoMashup Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
feedgeomashup_options_save (feed-geomashup.php:168)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Feed GeoMashup Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionfeedwordpress_admin_page_posts_meta_boxesfeed-geomashup.php:36
actionfeedwordpress_admin_page_posts_savefeed-geomashup.php:44
filtersyndicated_feed_itemsfeed-geomashup.php:248
filtersyndicated_feed_itemsfeed-geomashup.php:314
filtersyndicated_item_contentfeed-geomashup.php:332
actionpost_syndicated_itemfeed-geomashup.php:368
actionupdate_syndicated_itemfeed-geomashup.php:369
Maintenance & Trust

Feed GeoMashup Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedApr 23, 2015
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Feed GeoMashup Developer Profile

kwiliarty

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Feed GeoMashup

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

HTML Comments
<!-- posts-to-syndicate row --><!-- filter-mapped-posts row --><!-- filter-by-range row -->
Data Attributes
name="feedgeomashup_posts"name="feedgeomashup_filter_mapped_posts"name="feedgeomashup_latmin"name="feedgeomashup_latmax"name="feedgeomashup_longmin"name="feedgeomashup_longmax"
FAQ

Frequently Asked Questions about Feed GeoMashup