
IPGP Visitors Origin Security & Risk Analysis
wordpress.org/plugins/ipgp-visitors-originThis plugin will show you information about your website visitors: country, city, region, ISP. It will also show a map with the number of visitors fro …
Is IPGP Visitors Origin Safe to Use in 2026?
Generally Safe
Score 85/100IPGP Visitors Origin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The security posture of the "ipgp-visitors-origin" plugin v1.5 presents several significant concerns despite a clean vulnerability history. The static analysis reveals a substantial attack surface with two AJAX handlers, both lacking authentication checks. This is a critical oversight, as it exposes the plugin to potential unauthorized access and manipulation. Furthermore, the taint analysis indicates four high-severity flows with unsanitized paths, suggesting that user-controlled data might be processed in a way that could lead to vulnerabilities like cross-site scripting (XSS) or other code injection attacks. While the plugin does not utilize dangerous functions, perform file operations, or make external HTTP requests, and has a good percentage of SQL queries using prepared statements, these positive aspects are overshadowed by the identified entry points and taint issues. The absence of any recorded vulnerabilities in its history is a positive sign, implying either a lack of past exploitation or a diligent patching history, but it does not negate the current risks identified in the code analysis. Overall, the plugin's strengths lie in its limited use of vulnerable code patterns like direct file operations or external requests, but its weaknesses in input validation and access control on AJAX endpoints create a notable risk profile.
Key Concerns
- AJAX handlers without auth checks
- High severity taint flows
- Low percentage of properly escaped output
- Missing nonce checks
- Missing capability checks
IPGP Visitors Origin Security Vulnerabilities
IPGP Visitors Origin Release Timeline
IPGP Visitors Origin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
IPGP Visitors Origin Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 4
Maintenance & Trust
IPGP Visitors Origin Maintenance & Trust
Maintenance Signals
Community Trust
IPGP Visitors Origin Alternatives
WP Statistics – Simple, privacy-friendly Google Analytics alternative
wp-statistics
Get website traffic insights with GDPR/CCPA compliant, privacy-friendly analytics. Includes visitor data, stunning graphs, and no data sharing.
WP Visitor Statistics (Real Time Traffic)
wp-stats-manager
This plugin will help you to track your visitors & visits, browsers, operating systems, GEO locations and much more, easy to install and working fine.
Advanced Custom Fields: Multiple Coordinates
advanced-custom-fields-multiple-coordinates
This is an add-on to ACF that adds a field to select multiple Google Map points in a post.
Nearby Places Search
nearby-places-search
Nearby Places Search: This Plugin integrates with the Google Places and GMap.
Woo order google map location finder
woo-order-google-map-location-finder
Woo order google map location finder helps to find delivery location of ordered items.It is working with WooCommerce only.
IPGP Visitors Origin Developer Profile
9 plugins · 3K total installs
How We Detect IPGP Visitors Origin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/ipgp-visitors-origin/styles.css/wp-content/plugins/ipgp-visitors-origin/counter.js/wp-content/plugins/ipgp-visitors-origin/counter.jsHTML / DOM Fingerprints
data-map-locationsipgpvocounter[ipgp-report]