
subnetinfo Security & Risk Analysis
wordpress.org/plugins/subnet-infoProvides detailed information about the IP adress and subnet using a shortcode.
Is subnetinfo Safe to Use in 2026?
Generally Safe
Score 85/100subnetinfo has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "subnet-info" plugin v1.0.1 demonstrates an exceptionally strong security posture based on the provided static analysis and vulnerability history. The code analysis reveals no dangerous functions, no raw SQL queries, all output is properly escaped, and there are no file operations or external HTTP requests. Crucially, there are no identified taint flows, indicating that user-supplied data is not being processed in a way that could lead to exploitation. The absence of any known or historical vulnerabilities further reinforces this positive assessment. The plugin appears to be well-developed with security best practices at its core.
While the overall security is excellent, a single shortcode presents the sole entry point into the plugin. The static analysis reports zero unauthenticated AJAX handlers and zero unpermissioned REST API routes, which is a significant strength. However, the lack of explicit nonce and capability checks on the shortcode itself, even though it's the only entry point and there are no other apparent vulnerabilities, represents a minor area of potential, albeit low, risk. This is further compounded by the complete absence of any capability checks in the code signals. While the plugin's current functionality and lack of vulnerabilities suggest this may not be an immediate threat, it is a deviation from best practices for ensuring that even legitimate users are authorized to interact with plugin features.
In conclusion, "subnet-info" v1.0.1 is a highly secure plugin, free from known vulnerabilities and exhibiting strong internal coding practices. The primary area for improvement lies in implementing authorization checks for its shortcode, even in the absence of any detected vulnerabilities, to further harden its attack surface. The absence of any recorded vulnerabilities over time is a testament to the developers' commitment to security.
Key Concerns
- No capability checks implemented
- Shortcode entry point without explicit auth checks
subnetinfo Security Vulnerabilities
subnetinfo Code Analysis
subnetinfo Attack Surface
Shortcodes 1
WordPress Hooks 2
Maintenance & Trust
subnetinfo Maintenance & Trust
Maintenance Signals
Community Trust
subnetinfo Alternatives
atec Stats
atec-stats
Lightweight, beautiful and GDPR compliant WP statistics, including countries map (IPv4, IPv6, CDN & Multisite compatible).
IPv6 Detector
ipv6detector
Simple IPv6 detector widget for WordPress to show if user is connecting with IPv6 or IPv4.
Client IP Detector Plugin
client-ip-detector
A Simple widget to display client IP Address and print if the client is connecting via IPv6 or IPv4.
SaFly Curl Patch
safly-curl-patch
A plug-in which helps you solve the problems like 'WordPress could not establish a secure connection to WordPress.org.' caused by PHP Curl.
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
all-in-one-seo-pack
AIOSEO is the most powerful WordPress SEO plugin. Improve SEO rankings and traffic with comprehensive SEO tools and smart AI SEO optimizations!
subnetinfo Developer Profile
2 plugins · 50 total installs
How We Detect subnetinfo
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/subnet-info/css/style.csssubnet-info/style.css?ver=HTML / DOM Fingerprints
subnetinfo<!-- Start subnetinfo 1.0.1 --><p><b>[subnetinfo]</b> : No CIDR Notation subnet provided. For example 192.168.0.10/24</p><p><b>[subnetinfo]</b> : Invalid IP address or format.</p>