
Geolocator Security & Risk Analysis
wordpress.org/plugins/geolocatorGet website visitor's location based on IP address and show/hide specific content depending on country.
Is Geolocator Safe to Use in 2026?
Use With Caution
Score 59/100Geolocator has 1 unpatched vulnerability. Evaluate alternatives or apply available mitigations.
The geolocator plugin v1.1 presents a mixed security posture. While it demonstrates good practices by utilizing prepared statements for all SQL queries and a high percentage of properly escaped output, significant concerns arise from its vulnerability history and static analysis findings. The presence of a critical unpatched CVE related to deserialization of untrusted data is a major red flag, indicating a recurring and severe security flaw. Furthermore, the static analysis reveals the use of the dangerous `unserialize` function, which directly correlates with the type of historical vulnerability. Although the plugin boasts a low attack surface with no unprotected entry points, the single critical vulnerability and the potential for deserialization exploits overshadow these positives.
Key Concerns
- Unpatched critical CVE
- Critical taint flow found
- Use of unserialize function
- Zero nonce checks
- Zero capability checks
Geolocator Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Geolocator <= 1.1 - Unauthenticated PHP Object Injection
Geolocator Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
Geolocator Attack Surface
Shortcodes 3
WordPress Hooks 12
Maintenance & Trust
Geolocator Maintenance & Trust
Maintenance Signals
Community Trust
Geolocator Alternatives
User Location and IP
user-location-and-ip
User Location and IP is a free shortcode based Wordpress plugin that displays real-time information about your users, including their IP address, loca …
Ipgp User Country Flag
ipgp-user-country-flag
This plugin will allow you to show a flag of your visitors country. When a user goes to your website he will see a flag of its own country, based on t …
Foxlis Geo
foxlis-geo
Free! Get visitor's geo-location by ip-address. Redirect visitor by his city or country with smart options.
Geolocator Developer Profile
2 plugins · 60 total installs
How We Detect Geolocator
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/geolocator/vendor/autoload.php/wp-content/plugins/geolocator/classes/class.utilities.php/wp-content/plugins/geolocator/classes/class.location.php/wp-content/plugins/geolocator/classes/class.shortcodes.php/wp-content/plugins/geolocator/classes/class.posts.php/wp-content/plugins/geolocator/includes/widget.php/wp-content/plugins/geolocator/includes/settings.php/wp-content/plugins/geolocator/languagesHTML / DOM Fingerprints
<!-- Geolocator --><!-- Geolocator Main Metabox --><!-- Geolocator Post Settings -->data-geolocator-countrydata-geolocator-country-namedata-geolocator-latitudedata-geolocator-longitudegeolocator_options[geolocator][geolocator_show][geolocator_hide]