GT Foursquare Security & Risk Analysis

wordpress.org/plugins/gt-foursquare

Integrate Foursquare with WordPress. Features Map and List view.

10 active installs v1.0 PHP + WP 3.7+ Updated Dec 3, 2014
4squarecheck-infoursquarefoursquare-checkinssocial-media
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is GT Foursquare Safe to Use in 2026?

Generally Safe

Score 85/100

GT Foursquare has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The gt-foursquare plugin v1.0 exhibits a mixed security posture. While it demonstrates a positive absence of known CVEs and avoids dangerous functions, SQL queries, file operations, and external HTTP requests, significant concerns arise from its static analysis. The plugin completely lacks output escaping, meaning that any data rendered to the user interface is not sanitized, opening the door to potential cross-site scripting (XSS) vulnerabilities. Furthermore, the taint analysis revealed a flow with an unsanitized path, indicating a potential for data to be misused or lead to unintended consequences, even though it was not classified as critical or high severity.

The plugin's vulnerability history is clean, which is a positive sign and suggests the developers may have been cautious. However, the presence of an unsanitized path in the taint analysis and the complete lack of output escaping are critical weaknesses that overshadow the clean vulnerability history. The limited attack surface is a strength, but the identified code quality issues present a tangible risk that needs immediate attention. The absence of capability checks and nonce checks, while not directly flagged as a high risk due to the limited entry points, could become a vulnerability if the attack surface expands in future versions.

Key Concerns

  • No output escaping detected
  • Unsanitized path in taint flow
  • No capability checks
  • No nonce checks
Vulnerabilities
None known

GT Foursquare Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

GT Foursquare Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
17
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

0% escaped17 total outputs
Data Flows
1 unsanitized

Data Flow Analysis

1 flows1 with unsanitized paths
<settings-page> (includes\settings-page.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

GT Foursquare Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[gt4sq] gt4sq.php:461
WordPress Hooks 5
actiongt4sq-gmapsgt4sq.php:198
actionadmin_enqueue_scriptsgt4sq.php:427
actionadmin_menugt4sq.php:458
actioninitgt4sq.php:459
actionadmin_menugt4sq.php:460
Maintenance & Trust

GT Foursquare Maintenance & Trust

Maintenance Signals

WordPress version tested4.0.38
Last updatedDec 3, 2014
PHP min version
Downloads2K

Community Trust

Rating100/100
Number of ratings3
Active installs10
Developer Profile

GT Foursquare Developer Profile

globaltask

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect GT Foursquare

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gt-foursquare/gt4sq.js/wp-content/plugins/gt-foursquare/gt4sq.css
Script Paths
http://maps.google.com/maps/api/js?sensor=false

HTML / DOM Fingerprints

CSS Classes
gt4sq_wrappergt4sq_listgt4sq_mapgt4sq_sc_mapgt4sq_widget_map
Data Attributes
gt4sq_sc_gt4sq_sc_map_
JS Globals
locationsgoogle
Shortcode Output
[gt4sqGT FourSquare
FAQ

Frequently Asked Questions about GT Foursquare