Smartphone Location Lookup Security & Risk Analysis

wordpress.org/plugins/smartphone-location-lookup

This plugins displays a location based map on your sidebar. It tells visitors to your blog exactly where YOU are!

10 active installs v1.0.1 PHP + WP 3.0+ Updated Dec 19, 2010
google-mapsgps-lookuplocation-lookupmobile-gps-capabilitiessmartphone
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Smartphone Location Lookup Safe to Use in 2026?

Generally Safe

Score 85/100

Smartphone Location Lookup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 15yr ago
Risk Assessment

The "smartphone-location-lookup" plugin v1.0.1 presents a concerning security posture primarily due to a complete lack of output escaping. While the static analysis indicates a minimal attack surface and no obvious dangerous functions or unhandled taint flows, the fact that 0% of the 31 identified outputs are properly escaped is a significant weakness. This means that any data displayed by the plugin, whether user-provided or from internal sources, is potentially vulnerable to cross-site scripting (XSS) attacks. The absence of nonce checks and capability checks further exacerbates this risk, as there are no built-in mechanisms to verify user authorization or prevent unauthorized actions when data is outputted.

Furthermore, the plugin's vulnerability history is empty, which can be interpreted in two ways: either it has historically been very secure, or it has not been sufficiently tested or monitored for vulnerabilities. Given the current code analysis findings, particularly the unescaped output, the latter is a more plausible concern. The plugin's strengths lie in its small attack surface, use of prepared statements for SQL queries, and absence of file operations or external HTTP requests. However, these strengths are overshadowed by the critical flaw of unescaped output, which makes it susceptible to common web attacks. It is strongly recommended to address the output escaping issue immediately to mitigate the risk of XSS vulnerabilities.

Key Concerns

  • 0% of outputs properly escaped
  • No nonce checks
  • No capability checks
Vulnerabilities
None known

Smartphone Location Lookup Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Smartphone Location Lookup Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
2 prepared
Unescaped Output
31
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared2 total queries

Output Escaping

0% escaped31 total outputs
Attack Surface

Smartphone Location Lookup Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionwp_footerfunctions.php:287
actionwp_headfunctions.php:288
actionplugins_loadedsmartphone-location-lookup.php:13
Maintenance & Trust

Smartphone Location Lookup Maintenance & Trust

Maintenance Signals

WordPress version tested3.0.5
Last updatedDec 19, 2010
PHP min version
Downloads3K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Smartphone Location Lookup Developer Profile

rgubby

5 plugins · 180 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Smartphone Location Lookup

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

Shortcode Output
<p>unknown...</p><p><img src="http://maps.google.com/maps/api/staticmap?center=<p><img src="http://dev.virtualearth.net/REST/v1/Imagery/Map/Smartphone Location Lookup
FAQ

Frequently Asked Questions about Smartphone Location Lookup