
WP Geoloc Security & Risk Analysis
wordpress.org/plugins/wp-geolocSearch for posts around a location with a specific distance.
Is WP Geoloc Safe to Use in 2026?
Generally Safe
Score 85/100WP Geoloc has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "wp-geoloc" v1.0.2 plugin demonstrates a generally good security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, cron events, and file operations, combined with a limited attack surface (one shortcode), significantly reduces the potential for external exploitation. The code also shows some good practices like a reasonable percentage of SQL queries using prepared statements and several capability checks. However, a notable concern is the complete lack of nonce checks, which is a critical security measure for preventing Cross-Site Request Forgery (CSRF) attacks, especially when user-initiated actions occur. The taint analysis reporting zero flows with unsanitized paths and the clean vulnerability history (zero CVEs) are positive indicators, suggesting the plugin has historically been maintained with security in mind or has not been a significant target. Despite these strengths, the missing nonce checks represent a potential weakness that could be exploited.
Key Concerns
- Missing nonce checks
WP Geoloc Security Vulnerabilities
WP Geoloc Release Timeline
WP Geoloc Code Analysis
SQL Query Safety
Output Escaping
WP Geoloc Attack Surface
Shortcodes 1
WordPress Hooks 20
Maintenance & Trust
WP Geoloc Maintenance & Trust
Maintenance Signals
Community Trust
WP Geoloc Alternatives
OSM Categories
osm-categories
OpenStreetMap plugin to embed a map with markers to articles from different categories in different map layers.
Twitchers
twitchers
Twitcher allows people who visit your web site to post wildlife sightings and display them on a Google map. The plug-in only offers a front end google …
SlimStat Analytics
wp-slimstat
The leading web analytics plugin for WordPress
Geolocation IP Detection
geoip-detect
Provides geographic information detected by an IP adress.
Price Based on Country for WooCommerce
woocommerce-product-price-based-on-countries
Product Pricing and Currency based on Shopper's Country for WooCommerce with multi-currency support and geolocation to boost international sales.
WP Geoloc Developer Profile
1 plugin · 10 total installs
How We Detect WP Geoloc
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
HTML / DOM Fingerprints
fielderrorid="geolocation_nonce"id="locationField"id="autocomplete_message"id="autocomplete"id="formatted_address"id="latitude"+1 moreinitAutocompleteautocompletefillInAddress