AddWeb Woo Multi-address Security & Risk Analysis

wordpress.org/plugins/addweb-woo-multi-address

Manage and use multiple billing and shipping addresses in WooCommerce — with full support for classic, Elementor, and block-based checkouts.

0 active installs v1.0.0 PHP 7.0+ WP 5.0+ Updated Jul 14, 2025
billing-addresscheckoutmultiple-addressesshipping-addresswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is AddWeb Woo Multi-address Safe to Use in 2026?

Generally Safe

Score 100/100

AddWeb Woo Multi-address has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The "addweb-woo-multi-address" plugin, version 1.0.0, exhibits a mixed security posture. On the positive side, it demonstrates good practices by heavily utilizing prepared statements for SQL queries (96%) and proper output escaping (96%). The absence of known CVEs and external HTTP requests are also positive indicators. However, there are notable concerns regarding the attack surface and taint analysis results.

The plugin exposes 18 AJAX handlers, with a significant 4 of them lacking authentication checks. This presents a direct entry point for potential attackers. The taint analysis further highlights two flows with unsanitized paths, classified as high severity. While not explicitly a critical issue, these high-severity taint flows, coupled with the unprotected AJAX handlers, suggest a risk of potential remote code execution or data leakage if these pathways are exploited.

The plugin's vulnerability history is clean, with no recorded CVEs. This suggests either a good security track record or that it hasn't been a target of significant historical vulnerability discovery. However, this cannot solely mitigate the risks identified in the static analysis. The combination of a substantial attack surface with unprotected AJAX endpoints and high-severity taint flows necessitates careful consideration, despite the positive aspects like high SQL preparedness and output escaping.

Key Concerns

  • Unprotected AJAX handlers
  • High severity unsanitized taint flows
Vulnerabilities
None known

AddWeb Woo Multi-address Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

AddWeb Woo Multi-address Code Analysis

Dangerous Functions
0
Raw SQL Queries
4
102 prepared
Unescaped Output
10
222 escaped
Nonce Checks
16
Capability Checks
0
File Operations
2
External Requests
0
Bundled Libraries
1

Bundled Libraries

DataTables

SQL Query Safety

96% prepared106 total queries

Output Escaping

96% escaped232 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

10 flows2 with unsanitized paths
addwwomu_handle_address_data_by_pagination (addweb-woo-multi-address\addweb-woo-multi-address.php:311)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

AddWeb Woo Multi-address Attack Surface

Entry Points18
Unprotected4

AJAX Handlers 18

authwp_ajax_addwwomu_import_addressesaddweb-woo-multi-address\addweb-woo-multi-address.php:48
authwp_ajax_addwwomu_export_addresses_csvaddweb-woo-multi-address\addweb-woo-multi-address.php:54
authwp_ajax_addwwomu_get_paginated_address_tableaddweb-woo-multi-address\addweb-woo-multi-address.php:56
authwp_ajax_addwwomu_get_address_with_idaddweb-woo-multi-address\addweb-woo-multi-address.php:67
authwp_ajax_addwwomu_add_addressaddweb-woo-multi-address\addweb-woo-multi-address.php:70
authwp_ajax_addwwomu_edit_addressaddweb-woo-multi-address\addweb-woo-multi-address.php:71
authwp_ajax_addwwomu_delete_addressaddweb-woo-multi-address\addweb-woo-multi-address.php:72
noprivwp_ajax_addwwomu_set_default_addressaddweb-woo-multi-address\addweb-woo-multi-address.php:73
authwp_ajax_addwwomu_set_default_addressaddweb-woo-multi-address\addweb-woo-multi-address.php:74
authwp_ajax_addwwomu_import_addressesaddweb-woo-multi-address.php:48
authwp_ajax_addwwomu_export_addresses_csvaddweb-woo-multi-address.php:54
authwp_ajax_addwwomu_get_paginated_address_tableaddweb-woo-multi-address.php:56
authwp_ajax_addwwomu_get_address_with_idaddweb-woo-multi-address.php:67
authwp_ajax_addwwomu_add_addressaddweb-woo-multi-address.php:70
authwp_ajax_addwwomu_edit_addressaddweb-woo-multi-address.php:71
authwp_ajax_addwwomu_delete_addressaddweb-woo-multi-address.php:72
noprivwp_ajax_addwwomu_set_default_addressaddweb-woo-multi-address.php:73
authwp_ajax_addwwomu_set_default_addressaddweb-woo-multi-address.php:74
WordPress Hooks 34
actionbefore_woocommerce_initaddweb-woo-multi-address\addweb-woo-multi-address.php:47
actionwoocommerce_after_edit_account_address_formaddweb-woo-multi-address\addweb-woo-multi-address.php:51
actionwoocommerce_checkout_update_order_metaaddweb-woo-multi-address\addweb-woo-multi-address.php:58
actionwoocommerce_admin_order_data_after_billing_addressaddweb-woo-multi-address\addweb-woo-multi-address.php:61
actionadmin_menuaddweb-woo-multi-address\addweb-woo-multi-address.php:64
filterwoocommerce_custom_orders_table_supportedaddweb-woo-multi-address\addweb-woo-multi-address.php:77
filterwoocommerce_should_display_features_settingsaddweb-woo-multi-address\addweb-woo-multi-address.php:78
actionwp_enqueue_scriptsaddweb-woo-multi-address\addweb-woo-multi-address.php:81
actionadmin_enqueue_scriptsaddweb-woo-multi-address\addweb-woo-multi-address.php:82
actionwp_enqueue_scriptsaddweb-woo-multi-address\addweb-woo-multi-address.php:83
actioninitaddweb-woo-multi-address\addweb-woo-multi-address.php:85
actionwoocommerce_initaddweb-woo-multi-address\addweb-woo-multi-address.php:87
filterwoocommerce_store_api_checkout_update_order_from_requestaddweb-woo-multi-address\addweb-woo-multi-address.php:88
actionaddwwomu_delayed_importaddweb-woo-multi-address\addweb-woo-multi-address.php:91
actionwoocommerce_created_customeraddweb-woo-multi-address\addweb-woo-multi-address.php:93
actionwoocommerce_before_checkout_billing_formaddweb-woo-multi-address\addweb-woo-multi-address.php:96
actionwoocommerce_before_checkout_shipping_formaddweb-woo-multi-address\addweb-woo-multi-address.php:97
actionbefore_woocommerce_initaddweb-woo-multi-address.php:47
actionwoocommerce_after_edit_account_address_formaddweb-woo-multi-address.php:51
actionwoocommerce_checkout_update_order_metaaddweb-woo-multi-address.php:58
actionwoocommerce_admin_order_data_after_billing_addressaddweb-woo-multi-address.php:61
actionadmin_menuaddweb-woo-multi-address.php:64
filterwoocommerce_custom_orders_table_supportedaddweb-woo-multi-address.php:77
filterwoocommerce_should_display_features_settingsaddweb-woo-multi-address.php:78
actionwp_enqueue_scriptsaddweb-woo-multi-address.php:81
actionadmin_enqueue_scriptsaddweb-woo-multi-address.php:82
actionwp_enqueue_scriptsaddweb-woo-multi-address.php:83
actioninitaddweb-woo-multi-address.php:85
actionwoocommerce_initaddweb-woo-multi-address.php:87
filterwoocommerce_store_api_checkout_update_order_from_requestaddweb-woo-multi-address.php:88
actionaddwwomu_delayed_importaddweb-woo-multi-address.php:91
actionwoocommerce_created_customeraddweb-woo-multi-address.php:93
actionwoocommerce_before_checkout_billing_formaddweb-woo-multi-address.php:96
actionwoocommerce_before_checkout_shipping_formaddweb-woo-multi-address.php:97

Scheduled Events 2

addwwomu_delayed_import
addwwomu_delayed_import
Maintenance & Trust

AddWeb Woo Multi-address Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedJul 14, 2025
PHP min version7.0
Downloads835

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

AddWeb Woo Multi-address Developer Profile

AddWeb Solution

6 plugins · 80 total installs

88
trust score
Avg Security Score
91/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect AddWeb Woo Multi-address

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/addweb-woo-multi-address/assets/css/admin-style.css/wp-content/plugins/addweb-woo-multi-address/assets/css/style.css/wp-content/plugins/addweb-woo-multi-address/assets/js/admin-script.js/wp-content/plugins/addweb-woo-multi-address/assets/js/frontend-script.js
Script Paths
/wp-content/plugins/addweb-woo-multi-address/assets/js/admin-script.js/wp-content/plugins/addweb-woo-multi-address/assets/js/frontend-script.js
Version Parameters
addweb-woo-multi-address/assets/css/admin-style.css?ver=addweb-woo-multi-address/assets/css/style.css?ver=addweb-woo-multi-address/assets/js/admin-script.js?ver=addweb-woo-multi-address/assets/js/frontend-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
billing-selectaddwwomu_manage_address_sectionaddwwomu-address-formaddwwomu_edit_address_popupaddwwomu-address-itemaddwwomu_address_manager_wrapperaddwwomu-shipping-address-containeraddwwomu-billing-address-container+1 more
Data Attributes
data-noncedata-user-id
JS Globals
addwwomu_frontend_paramsaddwwomu_admin_params
FAQ

Frequently Asked Questions about AddWeb Woo Multi-address