
Whereabouts: Swarm Security & Risk Analysis
wordpress.org/plugins/whereabouts-swarmDisplay your current location, automatically updated by your latest Swarm check-in.
Is Whereabouts: Swarm Safe to Use in 2026?
Generally Safe
Score 85/100Whereabouts: Swarm has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The whereabouts-swarm plugin v0.5.0 presents a mixed security posture. On the positive side, there are no known CVEs, no bundled libraries, and all SQL queries are properly prepared, indicating good foundational security practices. The attack surface is also minimal, with no unprotected entry points identified through AJAX or REST API handlers. However, several areas raise concerns. The plugin exhibits a very low percentage of properly escaped output, meaning a significant portion of user-facing data could be vulnerable to Cross-Site Scripting (XSS) attacks. Furthermore, the taint analysis reveals two flows with unsanitized paths, which, while not categorized as critical or high severity in this analysis, represent a potential vector for data manipulation or execution if exploited. The absence of nonce checks and capability checks on its identified entry points (shortcodes and cron events) is a notable weakness, leaving these functions potentially open to unauthorized actions.
Key Concerns
- Low output escaping percentage
- Taint analysis shows unsanitized paths
- No nonce checks
- No capability checks
Whereabouts: Swarm Security Vulnerabilities
Whereabouts: Swarm Code Analysis
Output Escaping
Data Flow Analysis
Whereabouts: Swarm Attack Surface
Shortcodes 1
WordPress Hooks 7
Scheduled Events 1
Maintenance & Trust
Whereabouts: Swarm Maintenance & Trust
Maintenance Signals
Community Trust
Whereabouts: Swarm Alternatives
Whereabouts
whereabouts
Users can set their current location via the WordPress dashboard. A widget displays the location and the corresponding time (zone).
Geolocation
geolocation
Lightweight display the location information of your post in a map (GDPR comliant). Ideal for travelbloggers or anyone who would like to show the loca …
Simple Location
simple-location
Adds geographic location and weather support to WordPress.
GI Weather
gi-weather
GI Weather Plugin is a simple tool that help you to obtain current weather data for any city in the world.
Travel Routes
travel-routes
Display your travels on customizable maps !
Whereabouts: Swarm Developer Profile
2 plugins · 40 total installs
How We Detect Whereabouts: Swarm
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/whereabouts-swarm/css/whereabouts-swarm-admin.css/wp-content/plugins/whereabouts-swarm/js/whereabouts-swarm.min.jswhereabouts-swarm/css/whereabouts-swarm-admin.css?ver=js/whereabouts-swarm.min.js?ver=HTML / DOM Fingerprints
whereabouts-swarm-form<!-- Plugin Setup --><!-- Define include path for this plugin --><!-- Define url for this plugin --><!-- Define version -->+7 moredata-whereabouts-swarm-venue-icondata-whereabouts-swarm-venue-linkdata-whereabouts-swarm-venue-website-linkdata-whereabouts-swarm-venue-website-link-textwindow.whereabouts_swarm