
User IP and Location Security & Risk Analysis
wordpress.org/plugins/user-ip-and-locationWant to show your website visitors their IP address, location, and other cool details? This plugin makes it super easy! Now works perfectly with cachi …
Is User IP and Location Safe to Use in 2026?
Generally Safe
Score 100/100User IP and Location has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The 'user-ip-and-location' plugin version 4.0.2 presents a generally good security posture, with strong adherence to secure coding practices such as 100% use of prepared statements for SQL queries and a high percentage of properly escaped output. The absence of dangerous functions, file operations, and critical or high severity taint flows is commendable. However, there are specific areas that warrant attention. The presence of one unprotected REST API route represents a significant attack vector, as it could potentially be exploited without proper authentication. The vulnerability history, while not indicating currently unpatched critical issues, does show a past medium severity Cross-Site Scripting (XSS) vulnerability, which suggests the need for ongoing vigilance and thorough code reviews to prevent recurrence. Overall, the plugin demonstrates a solid foundation but requires careful monitoring and a focus on securing all entry points.
Key Concerns
- Unprotected REST API route found
- Past medium severity XSS vulnerability
- Flow with unsanitized paths in taint analysis
User IP and Location Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
User IP and Location <= 2.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode
User IP and Location Release Timeline
User IP and Location Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
User IP and Location Attack Surface
AJAX Handlers 1
REST API Routes 2
Shortcodes 5
WordPress Hooks 14
Maintenance & Trust
User IP and Location Maintenance & Trust
Maintenance Signals
Community Trust
User IP and Location Alternatives
GeoLooks – User IP & Location Finder
geolooks
Short Description: Display visitor IP address and location details using a shortcode.
Geo Controller
cf-geoplugin
Enhance your WordPress site with Geo Controller – a comprehensive plugin offering advanced location-based features and personalized content delivery.
User Location and IP
user-location-and-ip
User Location and IP is a free shortcode based Wordpress plugin that displays real-time information about your users, including their IP address, loca …
Show Visitor IP
show-visitor-ip
Show Visitor IP - Simply display visitor IP Address & visitor another location info using by IP on post or page, anywhere using shortcode.
Phone Country Autodetect for Forminator
phone-country-autodetect-for-forminator
Automatically detects the user's country and pre-fills Forminator's phone field with the correct international calling code. Uses ipapi.
User IP and Location Developer Profile
1 plugin · 3K total installs
How We Detect User IP and Location
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-ip-and-location/assets/js/user-ip-location.js/wp-content/plugins/user-ip-and-location/assets/js/user-ip-location.jsuser-ip-and-location/assets/js/user-ip-location.js?ver=HTML / DOM Fingerprints
user-ip-placeholderuser-ip-conditionaldata-typedata-heightdata-widthdata-vertical-aligndata-conditionsuserIpLocationData/wp-json/user-ip/v1/data<span class="user-ip-placeholder"<div class="user-ip-conditional"