Geo to Lat Security & Risk Analysis

wordpress.org/plugins/geo-to-lat

Converts Georgian characters in post, page and term slugs to Latin characters.

600 active installs v1.1 PHP + WP 4.0+ Updated Feb 22, 2026
georgianl10nlatinslugstransliteration
99
A · Safe
CVEs total1
Unpatched0
Last CVEFeb 16, 2026
Safety Verdict

Is Geo to Lat Safe to Use in 2026?

Generally Safe

Score 99/100

Geo to Lat has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Feb 16, 2026Updated 2mo ago
Risk Assessment

The "geo-to-lat" v1.1 plugin exhibits a strong security posture based on the provided static analysis. There are no identified AJAX handlers, REST API routes, shortcodes, or cron events, resulting in a remarkably small attack surface of zero entry points. This significantly reduces the potential for external exploitation. Furthermore, the code signals indicate good practices, with no dangerous functions identified and all identified SQL queries using prepared statements. All output is properly escaped, and there are no file operations or external HTTP requests. The absence of vulnerability history further reinforces this positive assessment, suggesting a history of secure development and maintenance.

However, the analysis does highlight some areas for potential improvement. The complete absence of nonce checks and capability checks across all code is a notable concern. While the attack surface is currently zero, if any new entry points were to be introduced in the future without proper authorization checks, this could easily lead to vulnerabilities. The taint analysis also reported zero flows, which is good, but the fact that it analyzed zero flows overall suggests that the analysis might not have been comprehensive enough to identify any potential risks. Despite these minor points, the plugin's current state is very secure.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
1 published

Geo to Lat Security Vulnerabilities

CVEs by Year

1 CVE in 2026
2026
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2026-32368medium · 6.5Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Geo to Lat <= 1.0.19 - Authenticated (Contributor+) SQL Injection

Feb 16, 2026 Patched in 1.1 (59d)
Version History

Geo to Lat Release Timeline

v1.1Current
v1.0.191 CVE
v1.0.181 CVE
v1.0.171 CVE
v1.0.161 CVE
v1.0.151 CVE
v1.0.141 CVE
v1.0.131 CVE
v1.0.121 CVE
v1.0.111 CVE
v1.0.101 CVE
v1.0.91 CVE
v1.0.81 CVE
v1.0.71 CVE
v1.0.61 CVE
v1.0.51 CVE
v1.0.41 CVE
v1.0.31 CVE
v1.0.21 CVE
v1.0.11 CVE
Code Analysis
Analyzed Mar 16, 2026

Geo to Lat Code Analysis

Dangerous Functions
0
Raw SQL Queries
2
2 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

50% prepared4 total queries
Attack Surface

Geo to Lat Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
filtersanitize_titlegeo-to-lat.php:48
filtersanitize_file_namegeo-to-lat.php:49
actionshutdowngeo-to-lat.php:73
Maintenance & Trust

Geo to Lat Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 22, 2026
PHP min version
Downloads71K

Community Trust

Rating100/100
Number of ratings2
Active installs600
Developer Profile

Geo to Lat Developer Profile

delphiknight

2 plugins · 600 total installs

88
trust score
Avg Security Score
100/100
Avg Patch Time
59 days
View full developer profile
Detection Fingerprints

How We Detect Geo to Lat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Geo to Lat