
Address Autocomplete Anything Security & Risk Analysis
wordpress.org/plugins/address-autocomplete-anythingEasily integrate Google Address Autocomplete to anything on your WordPress website!
Is Address Autocomplete Anything Safe to Use in 2026?
Generally Safe
Score 100/100Address Autocomplete Anything has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "address-autocomplete-anything" plugin version 1.2.6 exhibits a generally good security posture with several strong practices in place. The absence of raw SQL queries and a high percentage of properly escaped output are positive indicators. The plugin also demonstrates adherence to secure coding by using prepared statements for all SQL queries and has a clean vulnerability history with no recorded CVEs. This suggests a commitment to maintaining secure code over time.
However, a significant concern exists due to the presence of an unprotected AJAX handler. This represents a direct entry point into the plugin's functionality that is accessible to unauthenticated users, potentially leading to various vulnerabilities if not handled with extreme care within the handler itself. While the taint analysis shows no current unsanitized flows, the unprotected AJAX endpoint creates a prime target for attackers to inject malicious data or trigger unintended actions. The plugin also bundles the Select2 library, which could be a point of concern if it's an outdated version, though no specific information on its version or vulnerabilities is provided.
In conclusion, the plugin demonstrates a solid foundation in secure coding with its SQL handling and output escaping. The primary weakness lies in the single, unprotected AJAX entry point, which introduces a notable risk. Proactive monitoring for vulnerabilities and ensuring the Select2 library is up-to-date would further enhance its security. Addressing the unprotected AJAX handler should be a priority.
Key Concerns
- Unprotected AJAX handler found
- Bundled library (Select2) - potential risk
Address Autocomplete Anything Security Vulnerabilities
Address Autocomplete Anything Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Address Autocomplete Anything Attack Surface
AJAX Handlers 1
WordPress Hooks 11
Maintenance & Trust
Address Autocomplete Anything Maintenance & Trust
Maintenance Signals
Community Trust
Address Autocomplete Anything Alternatives
Address Autocomplete via Google for Gravity Forms
gf-google-address-autocomplete
A simple and nice plugin to get auto suggestion from google place api in gravity form address field.
Postcodes4U Address Finder
postcodes4u-address-finder
Requires WooCommerce at least: 2.2.3 Tested WooCommerce up to: 10.5.1 Tested ContactForm7 4.9.2 - 6.1.5 Tested Gravity Forms 2.4.15 - 2.9.
CodePros Autocomplete Address for WooCommerce
codepros-autocomplete-address-for-woocommerce
Enhance your WooCommerce checkout experience with Google Places address autocomplete functionality.
Autocomplete Address and Location Picker for WooCommerce
autocomplete-address-and-location-picker-for-woocommerce
Improve your WooCommerce checkout flow with Google Places address autocomplete, geocoding, and location picker tools. Supports Classic Checkout and Ch …
Autocomplete Location Field for Contact Form 7
autocomplete-location-field-contact-form-7
Add a Google Address Autocomplete field to Contact Form 7 forms. Powered by Google Places API for real-time address suggestions and accurate data coll …
Address Autocomplete Anything Developer Profile
5 plugins · 4K total installs
How We Detect Address Autocomplete Anything
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/address-autocomplete-anything/assets/css/admin.css/wp-content/plugins/address-autocomplete-anything/assets/js/select2/select2.min.js/wp-content/plugins/address-autocomplete-anything/assets/js/select2/select2.min.css/wp-content/plugins/address-autocomplete-anything/assets/js/select2/select2.min.jsaddress-autocomplete-anything/assets/css/admin.css?ver=address-autocomplete-anything/assets/js/select2/select2.min.js?ver=address-autocomplete-anything/assets/js/select2/select2.min.css?ver=HTML / DOM Fingerprints
wps-aa-adminwps-headerwps-logowps-header-link--documentationwps-header-link--reviewwps-header-link--feedbackwps-header-link--upgradewps-options-menu+4 morename="google_api_key"name="language"name="countries"WPS_AA_URLwps_aa