
User Location and IP Security & Risk Analysis
wordpress.org/plugins/user-location-and-ipUser Location and IP is a free shortcode based Wordpress plugin that displays real-time information about your users, including their IP address, loca …
Is User Location and IP Safe to Use in 2026?
Generally Safe
Score 100/100User Location and IP has a strong security track record. Known vulnerabilities have been patched promptly.
The 'user-location-and-ip' plugin v2.0 exhibits a generally good security posture due to its adherence to several WordPress security best practices. Notably, all SQL queries are prepared, and all identified output operations are properly escaped, significantly mitigating risks of SQL injection and cross-site scripting (XSS) vulnerabilities stemming from direct output. The absence of unprotected AJAX handlers, REST API routes, and cron events also limits the plugin's attack surface. However, there are several areas that warrant attention. The presence of one flow with unsanitized paths in taint analysis, even without critical or high severity, suggests a potential for vulnerabilities if not addressed. Furthermore, the lack of nonce checks on any entry points is a significant concern, as nonces are crucial for preventing Cross-Site Request Forgery (CSRF) attacks, especially on shortcodes that might perform actions. The plugin's vulnerability history shows one medium-severity CVE related to XSS, which, although patched, indicates a past weakness in input sanitization or output encoding that the current version should have fully addressed. While the current static analysis shows good practices, the past vulnerability and the taint flow merit careful review to ensure no residual risks remain.
Key Concerns
- Flow with unsanitized paths identified in taint analysis
- No nonce checks on any entry points (shortcode)
- Past medium severity XSS vulnerability (even if patched)
User Location and IP Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
User Location and IP <= 1.7 - Authenticated (Contributor+) Stored Cross-Site Scripting
User Location and IP Code Analysis
Output Escaping
Data Flow Analysis
User Location and IP Attack Surface
Shortcodes 1
WordPress Hooks 3
Maintenance & Trust
User Location and IP Maintenance & Trust
Maintenance Signals
Community Trust
User Location and IP Alternatives
User IP and Location
user-ip-and-location
Want to show your website visitors their IP address, location, and other cool details? This plugin makes it super easy! Now works perfectly with cachi …
Show Visitor IP
show-visitor-ip
Show Visitor IP - Simply display visitor IP Address & visitor another location info using by IP on post or page, anywhere using shortcode.
Add Region by Country for WooCommerce
add-region-by-country-for-woocommerce
Add Region by Country WooCommerce Add-on plug-in.
Region City Landing Pages Builder
region-city-landing-pages-builder
Build Multiple Geographically Targeted Landing Pages Quickly Using Generic Text & Automatically Inserted City Names.
Ipgp User Country Flag
ipgp-user-country-flag
This plugin will allow you to show a flag of your visitors country. When a user goes to your website he will see a flag of its own country, based on t …
User Location and IP Developer Profile
1 plugin · 400 total installs
How We Detect User Location and IP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/user-location-and-ip/flags//wp-content/plugins/user-location-and-ip/admin//wp-content/plugins/user-location-and-ip/inc/HTML / DOM Fingerprints
style="height:width:vertical-align:<img src="