Login IP & Country Restriction Security & Risk Analysis

wordpress.org/plugins/login-ip-country-restriction

Tighten your website security and fight against dictionary bot attacks originating from other countries, by denying access.

7K active installs v6.8.1 PHP 7.2+ WP 5.1+ Updated Nov 22, 2025
block-countryblock-ipcountry-firewallcountry-restrictionlogin-restriction
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Login IP & Country Restriction Safe to Use in 2026?

Generally Safe

Score 100/100

Login IP & Country Restriction has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 4mo ago
Risk Assessment

The plugin 'login-ip-country-restriction' v6.8.1 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, coupled with the plugin's robust use of prepared statements for SQL queries and a high percentage of properly escaped output, are strong indicators of secure development practices. The limited attack surface with zero entry points and a single external HTTP request, which likely handles a necessary external service for country restriction, also contribute positively to its security. Furthermore, the presence of nonce and capability checks, though minimal, suggests an awareness of security principles. However, the analysis doesn't provide a complete picture. The small number of analyzed flows in the taint analysis (only 1) means that while no critical or high-severity unsanitized paths were found, it's not conclusive evidence of complete safety. A more comprehensive taint analysis would be beneficial. The plugin's primary function likely involves IP and country data, which could potentially be sensitive, and while no issues are currently flagged, future updates or unforeseen interactions could introduce risks. Overall, the plugin appears to be built with security in mind, but further deeper analysis of its interaction with external services and a more extensive taint analysis would solidify this assessment.

Key Concerns

  • Limited Taint Analysis coverage
Vulnerabilities
None known

Login IP & Country Restriction Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Login IP & Country Restriction Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
5
191 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
1
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

97% escaped196 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<setup-debug> (inc\setup-debug.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Login IP & Country Restriction Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actionadmin_initlogin-restrict-country.php:223
actionadmin_initlogin-restrict-country.php:224
actionadmin_menulogin-restrict-country.php:225
actionadmin_noticeslogin-restrict-country.php:226
actionadmin_enqueue_scriptslogin-restrict-country.php:227
filtercheck_rule_type_savelogin-restrict-country.php:231
filterassess_rule_by_typelogin-restrict-country.php:234
actionadmin_noticeslogin-restrict-country.php:235
actionplugins_loadedlogin-restrict-country.php:238
filterauthenticatelogin-restrict-country.php:246
filterxmlrpc_enabledlogin-restrict-country.php:247
actionwp_loadedlogin-restrict-country.php:252
filterwp_loadedlogin-restrict-country.php:255
filtertemplate_redirectlogin-restrict-country.php:258
Maintenance & Trust

Login IP & Country Restriction Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedNov 22, 2025
PHP min version7.2
Downloads112K

Community Trust

Rating92/100
Number of ratings51
Active installs7K
Developer Profile

Login IP & Country Restriction Developer Profile

Iulia Cazan

8 plugins · 21K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
91 days
View full developer profile
Detection Fingerprints

How We Detect Login IP & Country Restriction

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/login-ip-country-restriction/css/style.css/wp-content/plugins/login-ip-country-restriction/js/script.js
Script Paths
/wp-content/plugins/login-ip-country-restriction/js/script.js
Version Parameters
login-ip-country-restriction/css/style.css?ver=login-ip-country-restriction/js/script.js?ver=

HTML / DOM Fingerprints

CSS Classes
slicr_notice
HTML Comments
<!-- Login IP & Country Restriction is active and this rule is NOT set. --><!-- Login IP & Country Restriction is active and this rule IS set. --><!-- The rule is set and we have restrictions. --><!-- IPs are restricted and this IP is NOT allowed. -->+9 more
Data Attributes
data-plugin-slug="slicr"
JS Globals
slicr_object
FAQ

Frequently Asked Questions about Login IP & Country Restriction