
ELEX WooCommerce Address Validation & Google Address Autocomplete Plugin Security & Risk Analysis
wordpress.org/plugins/address-validation-address-auto-completeSimple and easy to use address validation & google address autocomplete plugin. Uses EasyPost, UPS, USPS, AddressFinder & Google APIs.
Is ELEX WooCommerce Address Validation & Google Address Autocomplete Plugin Safe to Use in 2026?
Generally Safe
Score 100/100ELEX WooCommerce Address Validation & Google Address Autocomplete Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "address-validation-address-auto-complete" plugin v1.8.5 presents a mixed security posture. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries, avoiding dangerous functions, and having no file operations or known past vulnerabilities. The absence of critical or high severity taint flows is also reassuring.
However, there are notable concerns. The plugin has a relatively small attack surface, but two of its four AJAX handlers lack authentication checks. This means that unauthenticated users could potentially trigger these actions, opening up possibilities for abuse if the handlers themselves have logical flaws or interact with sensitive data. Additionally, while the majority of output is properly escaped, a significant portion (21%) is not, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is rendered without proper sanitization.
The plugin's vulnerability history is clean, with no recorded CVEs, which is a strong indicator of a generally well-maintained codebase. Nevertheless, the identified unprotected AJAX handlers and the percentage of unescaped output represent potential weaknesses that should be addressed to further strengthen its security.
Key Concerns
- Unprotected AJAX handlers
- Unescaped output exists
ELEX WooCommerce Address Validation & Google Address Autocomplete Plugin Security Vulnerabilities
ELEX WooCommerce Address Validation & Google Address Autocomplete Plugin Code Analysis
Output Escaping
ELEX WooCommerce Address Validation & Google Address Autocomplete Plugin Attack Surface
AJAX Handlers 4
WordPress Hooks 24
Maintenance & Trust
ELEX WooCommerce Address Validation & Google Address Autocomplete Plugin Maintenance & Trust
Maintenance Signals
Community Trust
ELEX WooCommerce Address Validation & Google Address Autocomplete Plugin Alternatives
Checkout Address AutoFill For WooCommerce
checkout-address-autofill-for-woocommerce
Checkout Address AutoFill For WooCommerce is a WooCommerce add-on which allows your user to autofill both Billing and Shipping address fields in the c …
Address Validation and Autocomplete for WooCommerce | Addressfinder
addressfinder-woo
Prevent failed deliveries and streamline checkout with verified address autocomplete for Australian and New Zealand WooCommerce stores.
AddySolution's address Autocomplete for WooCommerce
addy-autocomplete-woocommerce
AddySolutions's NZ Address Autocomplete will validate and suggest addresses as a user types to make online checkouts fast, easy and accurate.
Postcode.eu Address Validation
postcode-eu-address-validation
Address autocomplete and validation using the Postcode.eu API. Supports both Dutch and international addresses.
AutoComplete Address Checkout For WooCommerce
auto-complete-address-checkout-for-woocommerce
Speed up WooCommerce checkout with Google Places address autocomplete. Auto-fill billing & shipping address fields instantly — fewer errors, faste …
ELEX WooCommerce Address Validation & Google Address Autocomplete Plugin Developer Profile
22 plugins · 28K total installs
How We Detect ELEX WooCommerce Address Validation & Google Address Autocomplete Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/address-validation-address-auto-complete/assets/css/elex-address-validation-checkout.css/wp-content/plugins/address-validation-address-auto-complete/assets/css/elex-address-validation-admin.css/wp-content/plugins/address-validation-address-auto-complete/assets/js/elex-address-autocomplete.js/wp-content/plugins/address-validation-address-auto-complete/assets/js/elex-address-validation.js/wp-content/plugins/address-validation-address-auto-complete/assets/js/elex-address-autocomplete.js/wp-content/plugins/address-validation-address-auto-complete/assets/js/elex-address-validation.jsaddress-validation-address-auto-complete/assets/css/elex-address-validation-checkout.css?ver=address-validation-address-auto-complete/assets/css/elex-address-validation-admin.css?ver=address-validation-address-auto-complete/assets/js/elex-address-autocomplete.js?ver=address-validation-address-auto-complete/assets/js/elex-address-validation.js?ver=HTML / DOM Fingerprints
elex-address-validation-checkoutelex-address-validation-adminelex-address-autocompleteelex-address-validationdata-elex-autocompletedata-elex-validationElexAddressAutocomplete