Location Taxonomy Security & Risk Analysis

wordpress.org/plugins/location-taxonomy

Registers a hierarchical taxonomy to associate your posts with locations.

0 active installs v1.0.0 PHP 7.2+ WP 6.0+ Updated Nov 24, 2025
hierarchicallocationposttaxonomy
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Location Taxonomy Safe to Use in 2026?

Generally Safe

Score 100/100

Location Taxonomy has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The "location-taxonomy" plugin v1.0.0 exhibits a strong security posture based on the provided static analysis. There are no identified dangerous functions, SQL queries are 100% prepared, and all outputs are properly escaped. Furthermore, the plugin has no file operations, external HTTP requests, or bundled libraries, significantly reducing common attack vectors. The absence of AJAX handlers, REST API routes, shortcodes, and cron events limits the plugin's attack surface to zero, and crucially, all identified entry points (which are zero) are also unprotected, implying no exposed functionality for exploitation.

The vulnerability history further reinforces this positive assessment, showing zero known CVEs across all severity levels and no recorded common vulnerability types. This indicates a history of secure development and maintenance, or at least a lack of past exploitable issues. However, the complete lack of nonce and capability checks is a notable concern. While the current attack surface is zero, any future additions of AJAX handlers, REST API endpoints, or other interactive features would become immediately vulnerable without these fundamental security mechanisms.

In conclusion, the plugin is currently in an excellent security state with no identified vulnerabilities or exploitable code. Its adherence to secure coding practices for SQL and output handling is commendable. The primary weakness lies in the complete absence of nonce and capability checks, which, while not an immediate threat due to the zero attack surface, represents a significant future risk if the plugin's functionality expands.

Key Concerns

  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Location Taxonomy Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Location Taxonomy Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Location Taxonomy Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actioninitlocation-taxonomy.php:85
Maintenance & Trust

Location Taxonomy Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 24, 2025
PHP min version7.2
Downloads521

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Location Taxonomy Developer Profile

Felix Arntz

12 plugins · 18K total installs

91
trust score
Avg Security Score
95/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Location Taxonomy

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

REST Endpoints
/wp-json/wp/v2/locations
FAQ

Frequently Asked Questions about Location Taxonomy