
what3words Address Field Security & Risk Analysis
wordpress.org/plugins/3-word-address-validation-fieldOfficial plugin to allow customers to enter and validate a what3words address on your checkout for accurate deliveries.
Is what3words Address Field Safe to Use in 2026?
Generally Safe
Score 99/100what3words Address Field has a strong security track record. Known vulnerabilities have been patched promptly.
The "3-word-address-validation-field" plugin version 4.0.19 exhibits a mixed security posture. On the positive side, the static analysis reveals no immediate critical threats within its codebase. There are no identified dangerous functions, SQL queries are consistently prepared, and no external HTTP requests are made. The absence of shortcodes, cron events, and a significant attack surface with unprotected entry points is also reassuring. However, a notable concern is the low percentage (26%) of properly escaped output, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities, especially if the limited entry points are exploited in unexpected ways.
The plugin's vulnerability history is a significant red flag. It has a history of two known medium-severity vulnerabilities, including Cross-Site Request Forgery (CSRF) and Exposure of Sensitive Information. While currently none are unpatched, the recurrence of these types of vulnerabilities suggests a pattern of oversight in secure coding practices related to user input handling and permission enforcement. The fact that the last vulnerability was recorded in early 2025 also indicates that recent versions may still carry risks if not thoroughly audited.
In conclusion, while the plugin appears to have a clean bill of health from the immediate static analysis, the historical pattern of vulnerabilities and the significant number of unescaped output points are serious concerns. Developers should prioritize addressing the output escaping issues and continue to closely monitor for new vulnerabilities. The historical data suggests that while immediate critical risks might not be apparent, the potential for future exploitable flaws remains.
Key Concerns
- Medium severity vulnerabilities in history
- Low percentage of properly escaped output
what3words Address Field Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
what3words Address Field <= 4.0.15 - Cross-Site Request Forgery to Stored Cross-Site Scripting
what3words Address Field <= 4.0.0 - Authenticated (Administrator+) Sensitive Information Exposure in class-w3w-autosuggest-public.php
what3words Address Field Code Analysis
Output Escaping
what3words Address Field Attack Surface
WordPress Hooks 16
Maintenance & Trust
what3words Address Field Maintenance & Trust
Maintenance Signals
Community Trust
what3words Address Field Alternatives
Booking.com Official Search Box
bookingcom-official-searchbox
The official Booking.com search box is a user-friendly, customisable plugin to add the Booking.com search box to your own website in two easy steps.
Dexonline Searchbox
dexonline-searchbox
Dexonline Searchbox is a WordPress plugin that adds a searchbox on the sidebar to easily look up Romanian words definitions on dexonline.ro.
Priceline Partner Network WordPress Plugin
priceline-partner-network-official-searchbox
Easily add the Priceline travel widget to your own website in just a few clicks.
Site Kit by Google – Analytics, Search Console, AdSense, Speed
google-site-kit
Site Kit is a one-stop solution for WordPress users to use everything Google has to offer to make them successful on the web.
All in One SEO – Powerful SEO Plugin to Boost SEO Rankings & Increase Traffic
all-in-one-seo-pack
AIOSEO is the most powerful WordPress SEO plugin. Improve SEO rankings and traffic with comprehensive SEO tools and smart AI SEO optimizations!
what3words Address Field Developer Profile
1 plugin · 200 total installs
How We Detect what3words Address Field
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/3-word-address-validation-field/admin/css/w3w-autosuggest-admin.css/wp-content/plugins/3-word-address-validation-field/admin/js/w3w-autosuggest-admin.js/wp-content/plugins/3-word-address-validation-field/public/css/w3w-autosuggest-public.css/wp-content/plugins/3-word-address-validation-field/public/js/w3w-autosuggest-public.jshttps://cdn.what3words.com/javascript-components@4.9.0/dist/what3wordsw3w-autosuggest-public.css?ver=w3w-autosuggest-admin.css?ver=w3w-autosuggest-public.js?ver=w3w-autosuggest-admin.js?ver=HTML / DOM Fingerprints
w3w-autosuggest-wrapw3w-autosuggest-containerw3w-autosuggest-inputw3w-autosuggest-buttonw3w-autosuggest-resultsw3w-autosuggest-result-itemdata-w3w-plugin-versiondata-w3w-api-keyw3wAutosuggest/wp-json/w3w-autosuggest/v1/settings[w3w_autosuggest][w3w_address_field]