WP Engine GeoTarget Security & Risk Analysis

wordpress.org/plugins/wpengine-geoip

Create a personalized user experience based on location.

300 active installs v1.2.9 PHP + WP 3.0.1+ Updated Feb 3, 2025
geoipgeotargetlocalizationwpewpengine
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WP Engine GeoTarget Safe to Use in 2026?

Generally Safe

Score 92/100

WP Engine GeoTarget has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The wpengine-geoip plugin v1.2.9 exhibits a strong security posture based on the provided static analysis and vulnerability history. The code demonstrates adherence to best practices by employing prepared statements for all SQL queries, ensuring all output is properly escaped, and implementing a nonce check on its single AJAX handler. Crucially, there are no observed dangerous functions, file operations, or external HTTP requests, which significantly reduces the potential attack surface. The absence of any recorded CVEs, past or present, and no vulnerabilities identified in taint analysis further strengthens this assessment, suggesting a mature and well-maintained codebase.

While the overall security is good, a minor area for improvement is the absence of capability checks on the AJAX handler. Although the attack surface is small and protected by a nonce, implementing capability checks would add an extra layer of defense, ensuring that only authorized users can trigger the AJAX action. The lack of documented vulnerabilities is a positive indicator, implying a history of secure development. However, it's always prudent to remember that even secure plugins can have undiscovered vulnerabilities.

In conclusion, wpengine-geoip v1.2.9 appears to be a highly secure plugin. Its strengths lie in its robust handling of SQL and output, along with a clean vulnerability history. The only notable weakness is the lack of explicit capability checks on the AJAX endpoint, which is a minor concern given the presence of nonce checks and the plugin's overall limited attack surface. Users can generally have a high degree of confidence in the security of this plugin.

Key Concerns

  • AJAX handler missing capability checks
Vulnerabilities
None known

WP Engine GeoTarget Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

WP Engine GeoTarget Release Timeline

v1.2.9Current
v1.2.8
v1.2.7
v1.2.5
v1.2.4
v1.2.3
v1.2.2
v1.2.1
v1.2.0
v1.1.3
v1.1.2
v1.1.0
v1.0.2
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

WP Engine GeoTarget Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
11 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped11 total outputs
Attack Surface

WP Engine GeoTarget Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_geoip_dismiss_noticeclass-geoip.php:117
WordPress Hooks 5
actioninitclass-geoip.php:106
actioninitclass-geoip.php:107
actionadmin_enqueue_scriptsclass-geoip.php:110
actionadmin_initclass-geoip.php:113
actionadmin_noticesclass-geoip.php:114
Maintenance & Trust

WP Engine GeoTarget Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 3, 2025
PHP min version
Downloads75K

Community Trust

Rating72/100
Number of ratings15
Active installs300
Developer Profile

WP Engine GeoTarget Developer Profile

WP Engine

16 plugins · 3.5M total installs

73
trust score
Avg Security Score
91/100
Avg Patch Time
831 days
View full developer profile
Detection Fingerprints

How We Detect WP Engine GeoTarget

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Script Paths
/wp-content/plugins/wpengine-geoip/js/admin.js
Version Parameters
wpengine-geoip-admin-js?ver=wpengine-geoip/js/admin.js?ver=

HTML / DOM Fingerprints

JS Globals
window.nonce.create_nonce
Shortcode Output
[geoip-continent][geoip-country][geoip-region][geoip-city]
FAQ

Frequently Asked Questions about WP Engine GeoTarget