what3words Address Field Security & Risk Analysis

wordpress.org/plugins/3-word-address-validation-field

Official plugin to allow customers to enter and validate a what3words address on your checkout for accurate deliveries.

200 active installs v4.0.19 PHP + WP 4.7+ Updated Jan 6, 2026
3-word-addresssearchsearchboxthree-word-addresswhat3words
99
A · Safe
CVEs total2
Unpatched0
Last CVEFeb 14, 2025
Safety Verdict

Is what3words Address Field Safe to Use in 2026?

Generally Safe

Score 99/100

what3words Address Field has a strong security track record. Known vulnerabilities have been patched promptly.

2 known CVEsLast CVE: Feb 14, 2025Updated 2mo ago
Risk Assessment

The "3-word-address-validation-field" plugin version 4.0.19 exhibits a mixed security posture. On the positive side, the static analysis reveals no immediate critical threats within its codebase. There are no identified dangerous functions, SQL queries are consistently prepared, and no external HTTP requests are made. The absence of shortcodes, cron events, and a significant attack surface with unprotected entry points is also reassuring. However, a notable concern is the low percentage (26%) of properly escaped output, indicating a potential for Cross-Site Scripting (XSS) vulnerabilities, especially if the limited entry points are exploited in unexpected ways.

The plugin's vulnerability history is a significant red flag. It has a history of two known medium-severity vulnerabilities, including Cross-Site Request Forgery (CSRF) and Exposure of Sensitive Information. While currently none are unpatched, the recurrence of these types of vulnerabilities suggests a pattern of oversight in secure coding practices related to user input handling and permission enforcement. The fact that the last vulnerability was recorded in early 2025 also indicates that recent versions may still carry risks if not thoroughly audited.

In conclusion, while the plugin appears to have a clean bill of health from the immediate static analysis, the historical pattern of vulnerabilities and the significant number of unescaped output points are serious concerns. Developers should prioritize addressing the output escaping issues and continue to closely monitor for new vulnerabilities. The historical data suggests that while immediate critical risks might not be apparent, the potential for future exploitable flaws remains.

Key Concerns

  • Medium severity vulnerabilities in history
  • Low percentage of properly escaped output
Vulnerabilities
2

what3words Address Field Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
2

2 total CVEs

CVE-2025-26768medium · 6.1Cross-Site Request Forgery (CSRF)

what3words Address Field <= 4.0.15 - Cross-Site Request Forgery to Stored Cross-Site Scripting

Feb 14, 2025 Patched in 4.0.16 (5d)
CVE-2021-4428medium · 5.3Exposure of Sensitive Information to an Unauthorized Actor

what3words Address Field <= 4.0.0 - Authenticated (Administrator+) Sensitive Information Exposure in class-w3w-autosuggest-public.php

Jul 18, 2023 Patched in 4.0.1 (189d)
Code Analysis
Analyzed Mar 16, 2026

what3words Address Field Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
26
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

26% escaped35 total outputs
Attack Surface

what3words Address Field Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 16
actionwoocommerce_blocks_loadedincludes\class-w3w-autosuggest-blocks.php:18
actionwoocommerce_blocks_checkout_block_registrationincludes\class-w3w-autosuggest-blocks.php:19
actionwoocommerce_store_api_checkout_update_order_from_requestincludes\class-w3w-autosuggest-blocks.php:20
actionwp_enqueue_scriptsincludes\class-w3w-autosuggest-blocks.php:21
actionwoocommerce_after_order_detailsincludes\class-w3w-autosuggest-blocks.php:22
actionplugins_loadedincludes\class-w3w-autosuggest.php:175
actionadmin_menuincludes\class-w3w-autosuggest.php:212
actionadmin_noticesincludes\class-w3w-autosuggest.php:213
actionadmin_enqueue_scriptsincludes\class-w3w-autosuggest.php:214
actionadmin_enqueue_scriptsincludes\class-w3w-autosuggest.php:215
filterplugin_row_metaincludes\class-w3w-autosuggest.php:218
actionwp_enqueue_scriptsincludes\class-w3w-autosuggest.php:241
actionwp_enqueue_scriptsincludes\class-w3w-autosuggest.php:242
actionwoocommerce_order_details_after_customer_detailsincludes\class-w3w-autosuggest.php:243
filterscript_loader_tagincludes\class-w3w-autosuggest.php:244
filterwoocommerce_checkout_fieldsincludes\class-w3w-autosuggest.php:245
Maintenance & Trust

what3words Address Field Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 6, 2026
PHP min version
Downloads17K

Community Trust

Rating80/100
Number of ratings4
Active installs200
Developer Profile

what3words Address Field Developer Profile

what3words

1 plugin · 200 total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
97 days
View full developer profile
Detection Fingerprints

How We Detect what3words Address Field

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/3-word-address-validation-field/admin/css/w3w-autosuggest-admin.css/wp-content/plugins/3-word-address-validation-field/admin/js/w3w-autosuggest-admin.js/wp-content/plugins/3-word-address-validation-field/public/css/w3w-autosuggest-public.css/wp-content/plugins/3-word-address-validation-field/public/js/w3w-autosuggest-public.js
Script Paths
https://cdn.what3words.com/javascript-components@4.9.0/dist/what3words
Version Parameters
w3w-autosuggest-public.css?ver=w3w-autosuggest-admin.css?ver=w3w-autosuggest-public.js?ver=w3w-autosuggest-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
w3w-autosuggest-wrapw3w-autosuggest-containerw3w-autosuggest-inputw3w-autosuggest-buttonw3w-autosuggest-resultsw3w-autosuggest-result-item
Data Attributes
data-w3w-plugin-versiondata-w3w-api-key
JS Globals
w3wAutosuggest
REST Endpoints
/wp-json/w3w-autosuggest/v1/settings
Shortcode Output
[w3w_autosuggest][w3w_address_field]
FAQ

Frequently Asked Questions about what3words Address Field