GeoBuddy Security & Risk Analysis

wordpress.org/plugins/geobuddy

Enhance your GeoDirectory listings with modern social media fields and virtual tour integration. ---

0 active installs v1.0.4 PHP 7.2+ WP 5.0+ Updated Mar 1, 2026
business-directorycustom-fieldsgeodirectorysocial-mediavirtual-tour
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is GeoBuddy Safe to Use in 2026?

Generally Safe

Score 100/100

GeoBuddy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The static analysis of the 'geobuddy' plugin version 1.0.4 indicates a generally strong security posture with no identified critical vulnerabilities in its attack surface or code signals. The plugin demonstrates good practices by not utilizing dangerous functions, performing all SQL queries using prepared statements, and having a high percentage of properly escaped output. Furthermore, the absence of file operations and external HTTP requests reduces potential attack vectors. The plugin also exhibits a clean vulnerability history with zero recorded CVEs, suggesting consistent security maintenance over time.

However, there are a couple of areas that warrant attention. The complete lack of nonce checks and the low number of capability checks, especially given the presence of bundled libraries, could be a concern if certain functionalities were to be exposed without proper authorization mechanisms. While the current attack surface is reported as zero, future updates or additions could introduce vulnerabilities if these checks are not rigorously implemented.

In conclusion, 'geobuddy' v1.0.4 appears to be a secure plugin based on the provided static analysis and vulnerability history. Its adherence to secure coding practices for SQL and output handling is commendable. The primary area for vigilance would be ensuring proper authorization and nonce validation are implemented for any new features introduced in subsequent versions to maintain this strong security profile.

Key Concerns

  • 0 Nonce checks
  • 2 Capability checks
  • Bundled library Freemius v1.0 may be outdated
Vulnerabilities
None known

GeoBuddy Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

GeoBuddy Release Timeline

v1.0.4Current
v1.0.3
Code Analysis
Analyzed Mar 17, 2026

GeoBuddy Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
4
27 escaped
Nonce Checks
0
Capability Checks
2
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Freemius1.0

Output Escaping

87% escaped31 total outputs
Attack Surface

GeoBuddy Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 11
actionadmin_menuadmin\class-admin.php:40
actionadmin_initadmin\class-admin.php:41
actionadmin_enqueue_scriptsadmin\class-admin.php:42
actiongeobuddy_register_settings_tabsadmin\class-admin.php:48
actiongeobuddy_register_settings_tabsadmin\views\addon-tab-example.php:29
actiongeobuddy_register_settings_tabsadmin\views\addon-tab-example.php:63
actionplugins_loadedclass-geobuddy-plugin.php:27
actionadmin_noticesclass-geobuddy-plugin.php:44
filtergeodir_custom_fields_predefinedincludes\class-custom-fields.php:34
filtergeodir_custom_field_output_phone_key_whatsappincludes\class-custom-fields.php:36
filtergeodir_custom_field_output_text_key_skypeincludes\class-custom-fields.php:37
Maintenance & Trust

GeoBuddy Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedMar 1, 2026
PHP min version7.2
Downloads296

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

GeoBuddy Developer Profile

BuddyDevelopers

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GeoBuddy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/geobuddy/admin/css/geobuddy-admin.css/wp-content/plugins/geobuddy/admin/js/geobuddy-admin.js
Script Paths
/wp-content/plugins/geobuddy/admin/js/geobuddy-admin.js
Version Parameters
geobuddy/admin/css/geobuddy-admin.css?ver=geobuddy/admin/js/geobuddy-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
geobuddy-admin
Data Attributes
data-geobuddy-admin
JS Globals
geobuddy_fs
FAQ

Frequently Asked Questions about GeoBuddy