Fundify Geolocated Campaigns Security & Risk Analysis

wordpress.org/plugins/fundify-geolocated-campaigns

This plugin enables you to show your Fundify Geolocated campagins on Google map with shortcode

10 active installs v0.2 PHP + WP 3.5+ Updated Unknown
fundifygeolocationgoogle-maps
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Fundify Geolocated Campaigns Safe to Use in 2026?

Generally Safe

Score 100/100

Fundify Geolocated Campaigns has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin 'fundify-geolocated-campaigns' v0.2 exhibits a generally good security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, file operations, and known vulnerabilities is a strong positive. The use of prepared statements for all SQL queries is also a commendable practice. However, there are significant concerns regarding output escaping and the lack of capability checks on entry points. With only 14% of outputs properly escaped, there is a substantial risk of Cross-Site Scripting (XSS) vulnerabilities. The absence of capability checks on any of the identified entry points (AJAX handlers, shortcodes) means that any authenticated user, regardless of their role, could potentially interact with and manipulate these functions, leading to unauthorized actions or information disclosure.

Key Concerns

  • Low percentage of properly escaped output
  • No capability checks on entry points
Vulnerabilities
None known

Fundify Geolocated Campaigns Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Fundify Geolocated Campaigns Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
60
10 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

14% escaped70 total outputs
Attack Surface

Fundify Geolocated Campaigns Attack Surface

Entry Points3
Unprotected0

AJAX Handlers 2

noprivwp_ajax_vb_fgm_updaterinc\updater.php:176
authwp_ajax_vb_fgm_updaterinc\updater.php:177

Shortcodes 1

[fgm_campaigns] inc\shortcode.php:251
WordPress Hooks 17
actionwp_enqueue_scriptsfundify-geolocated-campaigns.php:36
actionwp_enqueue_scriptsfundify-geolocated-campaigns.php:51
actionadmin_enqueue_scriptsfundify-geolocated-campaigns.php:66
actionadmin_enqueue_scriptsfundify-geolocated-campaigns.php:82
actionadmin_noticesfundify-geolocated-campaigns.php:137
filteratcf_shortcode_submit_fieldsinc\custom-fields.php:74
actionatcf_shortcode_submit_save_field_latinc\custom-fields.php:90
actionatcf_shortcode_submit_save_field_lnginc\custom-fields.php:91
filteratcf_shortcode_submit_saved_data_latinc\custom-fields.php:97
filteratcf_shortcode_submit_saved_data_lnginc\custom-fields.php:98
actionatcf_metabox_campaign_info_afterinc\custom-fields.php:103
filteredd_metabox_fields_saveinc\custom-fields.php:108
actioninitinc\custom-fields.php:257
actionfgm_tab_fgm_map_helpinc\help.php:37
actionadmin_initinc\options-page.php:12
actionadmin_menuinc\options-page.php:13
actionfgm_tab_fgm_map_updaterinc\updater.php:56
Maintenance & Trust

Fundify Geolocated Campaigns Maintenance & Trust

Maintenance Signals

WordPress version tested3.7.41
Last updatedUnknown
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings1
Active installs10
Developer Profile

Fundify Geolocated Campaigns Developer Profile

Bobz

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Fundify Geolocated Campaigns

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/fundify-geolocated-campaigns/assets/css/style.css/wp-content/plugins/fundify-geolocated-campaigns/assets/js/infobubble.min.js/wp-content/plugins/fundify-geolocated-campaigns/assets/css/fgm-admin-style.css/wp-content/plugins/fundify-geolocated-campaigns/assets/js/admin-ajax-js.js
Script Paths
http://maps.googleapis.com/maps/api/js?key=/wp-content/plugins/fundify-geolocated-campaigns/assets/js/infobubble.min.js/wp-content/plugins/fundify-geolocated-campaigns/assets/js/admin-ajax-js.js

HTML / DOM Fingerprints

CSS Classes
map-canvas
Data Attributes
map-canvas
JS Globals
fgm_varmapinfoBubblelocations
Shortcode Output
[fgm_gmaps]
FAQ

Frequently Asked Questions about Fundify Geolocated Campaigns