Address Autocomplete Anything Security & Risk Analysis

wordpress.org/plugins/address-autocomplete-anything

Easily integrate Google Address Autocomplete to anything on your WordPress website!

900 active installs v1.2.6 PHP 7.4+ WP 5.0+ Updated Dec 9, 2025
addressautocompleteformgravityformswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Address Autocomplete Anything Safe to Use in 2026?

Generally Safe

Score 100/100

Address Autocomplete Anything has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3mo ago
Risk Assessment

The "address-autocomplete-anything" plugin version 1.2.6 exhibits a generally good security posture with several strong practices in place. The absence of raw SQL queries and a high percentage of properly escaped output are positive indicators. The plugin also demonstrates adherence to secure coding by using prepared statements for all SQL queries and has a clean vulnerability history with no recorded CVEs. This suggests a commitment to maintaining secure code over time.

However, a significant concern exists due to the presence of an unprotected AJAX handler. This represents a direct entry point into the plugin's functionality that is accessible to unauthenticated users, potentially leading to various vulnerabilities if not handled with extreme care within the handler itself. While the taint analysis shows no current unsanitized flows, the unprotected AJAX endpoint creates a prime target for attackers to inject malicious data or trigger unintended actions. The plugin also bundles the Select2 library, which could be a point of concern if it's an outdated version, though no specific information on its version or vulnerabilities is provided.

In conclusion, the plugin demonstrates a solid foundation in secure coding with its SQL handling and output escaping. The primary weakness lies in the single, unprotected AJAX entry point, which introduces a notable risk. Proactive monitoring for vulnerabilities and ensuring the Select2 library is up-to-date would further enhance its security. Addressing the unprotected AJAX handler should be a priority.

Key Concerns

  • Unprotected AJAX handler found
  • Bundled library (Select2) - potential risk
Vulnerabilities
None known

Address Autocomplete Anything Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Address Autocomplete Anything Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
61 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

85% escaped72 total outputs
Data Flows
All sanitized

Data Flow Analysis

3 flows
options_page (includes\admin\class-options.php:84)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Address Autocomplete Anything Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_wps_aa_dismiss_reviewincludes\admin\promos.php:55
WordPress Hooks 11
actionplugins_loadedaddress-autocomplete.php:26
actionadmin_menuincludes\admin\class-options.php:22
actionadmin_enqueue_scriptsincludes\admin\class-options.php:23
actionadmin_initincludes\admin\class-options.php:26
actionwps_aa_options_tab_settingsincludes\admin\class-options.php:29
actionadmin_initincludes\admin\class-options.php:32
actionadmin_noticesincludes\admin\class-options.php:33
actionwps_aa_header_linksincludes\admin\class-options.php:36
actionwps_aa_options_beforeincludes\admin\promos.php:2
actionadmin_noticesincludes\admin\promos.php:21
actionwp_headincludes\class-aa.php:33
Maintenance & Trust

Address Autocomplete Anything Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedDec 9, 2025
PHP min version7.4
Downloads12K

Community Trust

Rating100/100
Number of ratings14
Active installs900
Developer Profile

Address Autocomplete Anything Developer Profile

WP Sunshine

5 plugins · 4K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Address Autocomplete Anything

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/address-autocomplete-anything/assets/css/admin.css/wp-content/plugins/address-autocomplete-anything/assets/js/select2/select2.min.js/wp-content/plugins/address-autocomplete-anything/assets/js/select2/select2.min.css
Script Paths
/wp-content/plugins/address-autocomplete-anything/assets/js/select2/select2.min.js
Version Parameters
address-autocomplete-anything/assets/css/admin.css?ver=address-autocomplete-anything/assets/js/select2/select2.min.js?ver=address-autocomplete-anything/assets/js/select2/select2.min.css?ver=

HTML / DOM Fingerprints

CSS Classes
wps-aa-adminwps-headerwps-logowps-header-link--documentationwps-header-link--reviewwps-header-link--feedbackwps-header-link--upgradewps-options-menu+4 more
Data Attributes
name="google_api_key"name="language"name="countries"
JS Globals
WPS_AA_URLwps_aa
FAQ

Frequently Asked Questions about Address Autocomplete Anything