Guatemala States and Cities for WooCommerce Security & Risk Analysis

wordpress.org/plugins/wc-guatemala

Wordpress plugin that adds Cities and Zones from Guatemala to woocomerce. Spetially usefull for replacing the post code field, since guatemalans hardl …

50 active installs v3.0.4 PHP 7.4+ WP 5.8+ Updated Unknown
ciudadesdepartamentosguatemalastates-citieswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Guatemala States and Cities for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Guatemala States and Cities for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "wc-guatemala" plugin v3.0.4 exhibits a generally strong security posture based on the provided static analysis. The absence of known vulnerabilities, critical taint flows, and the presence of a relatively small attack surface are positive indicators. The plugin also demonstrates good practices in its handling of SQL queries, with a significant percentage utilizing prepared statements, and a high rate of output escaping.

However, there are notable areas of concern. The complete lack of nonce checks and capability checks across all entry points represents a significant security weakness. This means that any user, regardless of their logged-in status or role, could potentially trigger actions within the plugin. While the current static analysis didn't reveal immediate exploitable issues from this, it leaves the plugin highly susceptible to CSRF attacks if any functionality involves state-changing operations. The presence of file operations without explicit mention of security controls also warrants caution.

Given the zero vulnerability history, it's difficult to infer long-term patterns. However, this could indicate either a well-maintained plugin or simply a lack of past scrutiny. The strengths lie in the developers' apparent attention to SQL and output sanitization. The primary weakness is the significant oversight in authentication and authorization mechanisms for its entry points, which is a critical foundational security principle.

Key Concerns

  • Missing nonce checks on entry points
  • Missing capability checks on entry points
  • SQL queries not using prepared statements
  • Output not properly escaped
Vulnerabilities
None known

Guatemala States and Cities for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Guatemala States and Cities for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
11
4 prepared
Unescaped Output
9
38 escaped
Nonce Checks
0
Capability Checks
0
File Operations
1
External Requests
0
Bundled Libraries
0

SQL Query Safety

27% prepared15 total queries

Output Escaping

81% escaped47 total outputs
Attack Surface

Guatemala States and Cities for WooCommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[fee] includes\filter-by-cities.php:269
WordPress Hooks 14
filterwoocommerce_package_ratesincludes\filter-by-cities.php:174
actionplugins_loadedincludes\states-places.php:20
actionadmin_noticesincludes\states-places.php:21
filterwoocommerce_statesincludes\states-places.php:45
filterwoocommerce_billing_fieldsincludes\states-places.php:53
filterwoocommerce_shipping_fieldsincludes\states-places.php:54
filterwoocommerce_form_field_cityincludes\states-places.php:55
actionwp_enqueue_scriptsincludes\states-places.php:57
actionwp_headincludes\states-places.php:58
filterwoocommerce_shipping_methodswc-guatemala-departamentos-y-ciudades.php:59
actionwoocommerce_shipping_initwc-guatemala-departamentos-y-ciudades.php:66
actionadmin_noticeswc-guatemala-departamentos-y-ciudades.php:77
actionplugins_loadedwc-guatemala-departamentos-y-ciudades.php:84
filterwoocommerce_default_address_fieldswc-guatemala-departamentos-y-ciudades.php:96
Maintenance & Trust

Guatemala States and Cities for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedUnknown
PHP min version7.4
Downloads2K

Community Trust

Rating100/100
Number of ratings4
Active installs50
Developer Profile

Guatemala States and Cities for WooCommerce Developer Profile

Edwin Xico (XicoOfficial)

6 plugins · 100 total installs

87
trust score
Avg Security Score
90/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Guatemala States and Cities for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-guatemala/dist/assets/css/wc-guatemala.css/wp-content/plugins/wc-guatemala/dist/assets/js/wc-guatemala.js
Script Paths
/wp-content/plugins/wc-guatemala/dist/assets/js/wc-guatemala.js
Version Parameters
wc-guatemala/dist/assets/css/wc-guatemala.css?ver=wc-guatemala/dist/assets/js/wc-guatemala.js?ver=

HTML / DOM Fingerprints

CSS Classes
notice-infois-dismissible
Data Attributes
data-plugin-path
JS Globals
DL_WC_GUATEMALA_PLUGIN_PATHDL_WC_GUATEMALA_PLUGIN_URL
Shortcode Output
<a class="button button-primary" href="https://coders.club.gt/shipping-guatemala.php">Suscribete Gratis</a>
FAQ

Frequently Asked Questions about Guatemala States and Cities for WooCommerce