IP Address Approval Security & Risk Analysis

wordpress.org/plugins/ip-address-approval

The IP Address Approval system provides an easy way for you to Allow or Block access to your website to protect your site from unwanted visitors.

100 active installs v1.9.2 PHP + WP 4.6+ Updated Jun 11, 2025
geo-locationgeo-redirectgeo-securityip-blockerstop-spam
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is IP Address Approval Safe to Use in 2026?

Generally Safe

Score 100/100

IP Address Approval has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11mo ago
Risk Assessment

The "ip-address-approval" plugin v1.9.2 exhibits a generally good security posture due to the absence of known vulnerabilities and a well-controlled attack surface. All identified entry points, including the single AJAX handler, appear to have proper authorization checks. The plugin also demonstrates strong practices by using prepared statements for all SQL queries and avoiding file operations and external HTTP requests. The presence of nonce and capability checks further bolsters its security. However, a significant concern arises from the taint analysis, which identified two flows with unsanitized paths. While these did not reach critical or high severity, they represent potential avenues for security weaknesses if exploited, particularly if they interact with sensitive data or system functions. Furthermore, the low percentage (8%) of properly escaped outputs suggests a potential for Cross-Site Scripting (XSS) vulnerabilities, especially given the large number of output operations. The lack of recorded vulnerabilities historically is a positive sign, indicating a generally stable codebase, but it doesn't negate the risks identified in the static and taint analysis.

Key Concerns

  • Taint flows with unsanitized paths found
  • Low percentage of properly escaped outputs
Vulnerabilities
None known

IP Address Approval Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

IP Address Approval Release Timeline

v1.9.2Current
v1.9.1
v1.9.0
v1.8.3
v1.8.2
v1.8.1
v1.8.0
v1.7.0
v1.6.0
v1.5.3
v1.5.2
v1.5.1
v1.5.0
v1.4.5
v1.4.4
v1.4.3
v1.4.2
v1.4.1
v1.4.0
v1.3.0
Code Analysis
Analyzed Mar 16, 2026

IP Address Approval Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
1 prepared
Unescaped Output
177
15 escaped
Nonce Checks
4
Capability Checks
3
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared1 total queries

Output Escaping

8% escaped192 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
ip_approval_checker_process (ip-approval.php:25)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

IP Address Approval Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_ip_approval_ajax_actionincludes\is-admin.php:19
WordPress Hooks 8
actioninitincludes\is-admin.php:94
actioninitincludes\is-admin.php:105
actionadmin_menuincludes\is-admin.php:115
filterplugin_row_metaincludes\is-admin.php:117
actionadmin_bar_menuincludes\utils.php:53
actionadmin_initincludes\utils.php:54
actionget_headerip-approval.php:53
filterlogin_initip-approval.php:77
Maintenance & Trust

IP Address Approval Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJun 11, 2025
PHP min version
Downloads8K

Community Trust

Rating74/100
Number of ratings3
Active installs100
Developer Profile

IP Address Approval Developer Profile

IP Address Approval

1 plugin · 100 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect IP Address Approval

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/ip-address-approval/assets/css/ip-approval-css.css/wp-content/plugins/ip-address-approval/assets/js/jquery.filtertable.min.js/wp-content/plugins/ip-address-approval/assets/js/jquery.tablesorter.min.js/wp-content/plugins/ip-address-approval/assets/js/ip-approval-js.js
Version Parameters
ip-address-approval/assets/css/ip-approval-css.css?ver=ip-address-approval/assets/js/jquery.filtertable.min.js?ver=ip-address-approval/assets/js/jquery.tablesorter.min.js?ver=ip-address-approval/assets/js/ip-approval-js.js?ver=

HTML / DOM Fingerprints

CSS Classes
ip-save
HTML Comments
<!-- Add IP Approval IP Checker to website/blog --><!-- Add IP Approval IP Checker to login --><!-- CHECK FOR API --><!-- AUTOLOAD -->+3 more
Data Attributes
title="Save Changes"
FAQ

Frequently Asked Questions about IP Address Approval