Widget para añadir la IP Pública de nuestros visitantes Security & Risk Analysis

wordpress.org/plugins/mostrar-ip-publica-widget-texto

Este Plugin nos muestra en cualquier lugar que se pueda añadir un Widget de texto la IP de nuestros visitantes.

10 active installs v1.0 PHP + WP 1.0+ Updated Jun 22, 2016
ippublicatextovisitanteswidget
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Widget para añadir la IP Pública de nuestros visitantes Safe to Use in 2026?

Generally Safe

Score 85/100

Widget para añadir la IP Pública de nuestros visitantes has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 9yr ago
Risk Assessment

The "mostrar-ip-publica-widget-texto" v1.0 plugin exhibits a mixed security posture. On one hand, it demonstrates strong practices in handling SQL queries, exclusively using prepared statements, and has no recorded vulnerability history, suggesting a generally stable codebase. It also lacks any reported CVEs, which is a positive sign. However, the static analysis reveals significant concerns. The presence of the `create_function` is a critical security risk due to its ability to execute arbitrary code. Furthermore, a substantial portion of output (83%) is not properly escaped, creating a high risk of Cross-Site Scripting (XSS) vulnerabilities, especially considering the absence of nonce checks or capability checks on any entry points, although the attack surface is currently reported as zero. The lack of taint analysis data could also mask potential vulnerabilities if the plugin were to evolve and introduce more dynamic inputs. The complete absence of nonces and capability checks on any potential entry points, coupled with the unescaped output, presents a significant risk, even with a reported zero attack surface.

Overall, while the plugin benefits from a clean vulnerability history and secure SQL practices, the identified code signals, particularly `create_function` and the high rate of unescaped output, introduce severe risks. The lack of defensive checks like nonces and capability checks further exacerbates these risks, leaving it vulnerable to code execution and XSS attacks if new entry points are introduced or if existing, undetected entry points exist. The current security posture is concerning due to these fundamental flaws.

Key Concerns

  • Dangerous function create_function used
  • High percentage of unescaped output (83%)
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Widget para añadir la IP Pública de nuestros visitantes Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Widget para añadir la IP Pública de nuestros visitantes Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Widget para añadir la IP Pública de nuestros visitantes Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
10
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

create_functionadd_action( 'widgets_init', create_function('', 'return register_widget("vdd_IP_publica_Widget");') widget-ip-publica.php:96

Output Escaping

17% escaped12 total outputs
Attack Surface

Widget para añadir la IP Pública de nuestros visitantes Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 1
actionwidgets_initwidget-ip-publica.php:96
Maintenance & Trust

Widget para añadir la IP Pública de nuestros visitantes Maintenance & Trust

Maintenance Signals

WordPress version tested4.4.34
Last updatedJun 22, 2016
PHP min version
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Widget para añadir la IP Pública de nuestros visitantes Developer Profile

mavksoftes

2 plugins · 20 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Widget para añadir la IP Pública de nuestros visitantes

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

CSS Classes
vdd_IP_publica_Widget
Data Attributes
id="vdd_IP_publica_Widget"id="vdd_IP_publica_Widget-title"name="vdd_IP_publica_Widget-title"id="vdd_IP_publica_Widget-showlink"name="vdd_IP_publica_Widget-showlink"
Shortcode Output
Mas servicios en MavkSoft
FAQ

Frequently Asked Questions about Widget para añadir la IP Pública de nuestros visitantes