Phone Country Autodetect for Forminator Security & Risk Analysis

wordpress.org/plugins/phone-country-autodetect-for-forminator

Automatically detects the user's country and pre-fills Forminator's phone field with the correct international calling code. Uses ipapi.

20 active installs v1.0.1 PHP 7.2+ WP 5.0+ Updated Aug 15, 2025
auto-countrycountry-codeforminatorip-geolocationphone-field
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Phone Country Autodetect for Forminator Safe to Use in 2026?

Generally Safe

Score 100/100

Phone Country Autodetect for Forminator has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 7mo ago
Risk Assessment

The "phone-country-autodetect-for-forminator" plugin v1.0.1 exhibits a strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits its attack surface. Furthermore, the code demonstrates good development practices with 100% of SQL queries using prepared statements and all identified outputs being properly escaped. There are no identified dangerous functions or file operations, and the taint analysis shows no unsanitized paths.

However, there are a few areas that warrant attention. The presence of an external HTTP request without further context could be a potential vector for issues if not handled securely. While there are no recorded past vulnerabilities, this does not guarantee future security. The complete absence of nonce checks and capability checks across the entire plugin is a notable weakness. While the static analysis reported zero entry points, this might be a limitation of the analysis itself or indicate a plugin that is purely a frontend enhancement. If there are any hidden or dynamically generated entry points not captured, the lack of these fundamental security checks could expose the site to risks.

In conclusion, the plugin appears to be developed with security in mind, as evidenced by its clean code signals and lack of historical vulnerabilities. The limited attack surface is a significant strength. The primary concerns stem from the external HTTP request and the absence of nonce and capability checks, which are fundamental security mechanisms in WordPress. Future development should consider implementing these checks to further harden the plugin.

Key Concerns

  • External HTTP request
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Phone Country Autodetect for Forminator Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Phone Country Autodetect for Forminator Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
2 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

100% escaped2 total outputs
Attack Surface

Phone Country Autodetect for Forminator Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_menuincludes\settings-page.php:4
actionadmin_initincludes\settings-page.php:15
filterforminator_field_phone_markupphone-country-autodetect-for-forminator.php:20
Maintenance & Trust

Phone Country Autodetect for Forminator Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 15, 2025
PHP min version7.2
Downloads233

Community Trust

Rating0/100
Number of ratings0
Active installs20
Developer Profile

Phone Country Autodetect for Forminator Developer Profile

Huseyin Mardinli

1 plugin · 20 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Phone Country Autodetect for Forminator

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Phone Country Autodetect for Forminator