
GeoLooks – User IP & Location Finder Security & Risk Analysis
wordpress.org/plugins/geolooksShort Description: Display visitor IP address and location details using a shortcode.
Is GeoLooks – User IP & Location Finder Safe to Use in 2026?
Generally Safe
Score 100/100GeoLooks – User IP & Location Finder has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The geolooks plugin v1.0.0 exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The code demonstrates excellent practices by utilizing prepared statements for all SQL queries and properly escaping nearly all output, significantly reducing the risk of SQL injection and cross-site scripting (XSS) vulnerabilities. The absence of dangerous functions, file operations, and recorded vulnerabilities further strengthens this positive assessment. The limited attack surface, with only one shortcode and no identified unprotected entry points, is also a positive indicator.
However, several areas warrant attention. The complete lack of nonce checks and capability checks across all identified entry points, including the single shortcode, presents a notable security gap. This means that actions triggered by the shortcode could potentially be performed by any authenticated user, regardless of their intended permissions, opening the door for privilege escalation or unauthorized actions. While taint analysis found no issues, the absence of taint flows analyzed could indicate limited testing or complexity that wasn't captured. The single external HTTP request also represents a potential, albeit minor, attack vector if the target endpoint is compromised or malicious.
In conclusion, geolooks v1.0.0 has a solid foundation with its secure handling of SQL and output. The primary weakness lies in the insufficient authorization and validation mechanisms for its entry points. Addressing the missing nonce and capability checks is crucial to harden the plugin against potential abuse and ensure that actions are only performed by authorized users.
Key Concerns
- No nonce checks on entry points
- No capability checks on entry points
- External HTTP request without further analysis
GeoLooks – User IP & Location Finder Security Vulnerabilities
GeoLooks – User IP & Location Finder Code Analysis
Output Escaping
GeoLooks – User IP & Location Finder Attack Surface
Shortcodes 1
WordPress Hooks 5
Maintenance & Trust
GeoLooks – User IP & Location Finder Maintenance & Trust
Maintenance Signals
Community Trust
GeoLooks – User IP & Location Finder Alternatives
User IP and Location
user-ip-and-location
Want to show your website visitors their IP address, location, and other cool details? This plugin makes it super easy! Now works perfectly with cachi …
Live User IP and Location
live-user-ip-and-location
Display visitor IP and location using ipapi.co with caching, API test, TTL control, and optional IP anonymization.
Geo Controller
cf-geoplugin
Enhance your WordPress site with Geo Controller – a comprehensive plugin offering advanced location-based features and personalized content delivery.
User Location and IP
user-location-and-ip
User Location and IP is a free shortcode based Wordpress plugin that displays real-time information about your users, including their IP address, loca …
Show Visitor IP
show-visitor-ip
Show Visitor IP - Simply display visitor IP Address & visitor another location info using by IP on post or page, anywhere using shortcode.
GeoLooks – User IP & Location Finder Developer Profile
11 plugins · 3K total installs
How We Detect GeoLooks – User IP & Location Finder
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/geolooks/assets/css/main.css/wp-content/plugins/geolooks/assets/css/admin-main.cssgeolooks/assets/css/main.css?ver=geolooks/assets/css/admin-main.css?ver=HTML / DOM Fingerprints
user-ip-info-wrapip-info-card-style-error-occurred-alertip-info-card-style-geolooks_ipinfo[geolooks_user_locator]