whats-my-ip Security & Risk Analysis

wordpress.org/plugins/whats-my-ip

Display the current User's IP address in Widgets & Shortcodes.

10 active installs v0.5.2 PHP + WP 3.5.0+ Updated Aug 7, 2014
geoipip
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is whats-my-ip Safe to Use in 2026?

Generally Safe

Score 85/100

whats-my-ip has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 11yr ago
Risk Assessment

The "whats-my-ip" plugin version 0.5.2 exhibits a remarkably clean static analysis report. There are no identified entry points such as AJAX handlers, REST API routes, shortcodes, or cron events, which significantly reduces the potential attack surface. Furthermore, the code demonstrates excellent security practices by utilizing prepared statements for all SQL queries and ensuring all output is properly escaped. The absence of dangerous functions, file operations, external HTTP requests, and bundled libraries also contributes to a strong security posture. The plugin's vulnerability history is also completely clear, with no known CVEs or past vulnerabilities, indicating a history of secure development and maintenance.

While the lack of identified vulnerabilities and entry points is highly positive, the complete absence of nonce checks and capability checks across any potential (though currently non-existent) entry points is a theoretical weakness. If future versions were to introduce any user-facing functionality, the lack of these fundamental WordPress security measures would immediately become a critical concern. However, based solely on the provided data for version 0.5.2, the plugin appears to be exceptionally secure with no actionable security risks.

Vulnerabilities
None known

whats-my-ip Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

whats-my-ip Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

whats-my-ip Attack Surface

Entry Points0
Unprotected0
Maintenance & Trust

whats-my-ip Maintenance & Trust

Maintenance Signals

WordPress version tested3.9.40
Last updatedAug 7, 2014
PHP min version
Downloads3K

Community Trust

Rating46/100
Number of ratings3
Active installs10
Developer Profile

whats-my-ip Developer Profile

Darshan Sawardekar

6 plugins · 70 total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect whats-my-ip

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/whats-my-ip/resources/css/whats-my-ip.css/wp-content/plugins/whats-my-ip/resources/js/whats-my-ip.js
Script Paths
/wp-content/plugins/whats-my-ip/resources/js/whats-my-ip.js
Version Parameters
whats-my-ip/resources/css/whats-my-ip.css?ver=whats-my-ip/resources/js/whats-my-ip.js?ver=

HTML / DOM Fingerprints

Shortcode Output
<!--WhatsMyIP START--><!--WhatsMyIP END-->
FAQ

Frequently Asked Questions about whats-my-ip