
All Countries Counties For WooCommerce Security & Risk Analysis
wordpress.org/plugins/all-countries-counties-for-wcA Wordpress WooCommerce Plugin that add counties/provinces/states for WooCommerce Countries
Is All Countries Counties For WooCommerce Safe to Use in 2026?
Generally Safe
Score 85/100All Countries Counties For WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "all-countries-counties-for-wc" plugin, version 1.1.1, presents a generally good security posture based on the static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the code analysis indicates a commitment to secure coding practices, with no dangerous functions identified, all SQL queries utilizing prepared statements, and no file operations or external HTTP requests. The lack of critical or high severity taint flows is also a positive sign.
However, there are minor areas of concern. The output escaping is only 50% properly implemented, meaning that half of the outputs are not escaped, which could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if untrusted data is directly outputted. The complete absence of nonce checks and capability checks across all entry points is also a notable weakness. While the current attack surface is zero, if any new entry points are introduced in future versions without these crucial security measures, it would create significant vulnerabilities. The plugin also has no recorded vulnerability history, which is a strong indicator of its past security performance, but this doesn't negate the potential risks identified in the current code analysis.
In conclusion, the plugin is strong in its limited attack surface and use of prepared statements. The primary weaknesses lie in the incomplete output escaping and the complete lack of nonce and capability checks, which represent potential risks that should be addressed to further harden the plugin's security. The clean vulnerability history is a positive, but the static analysis reveals areas for improvement.
Key Concerns
- Half of outputs are not properly escaped
- No nonce checks implemented
- No capability checks implemented
All Countries Counties For WooCommerce Security Vulnerabilities
All Countries Counties For WooCommerce Code Analysis
Output Escaping
All Countries Counties For WooCommerce Attack Surface
WordPress Hooks 10
Maintenance & Trust
All Countries Counties For WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
All Countries Counties For WooCommerce Alternatives
Product Filter for WooCommerce by WBW
woo-product-filter
Filter products by categories, attributes, prices, and more. Elementor Compatibility. Shoppers easily find products with WooCommerce Product Filter
Klarna for WooCommerce
klarna-payments-for-woocommerce
Grow your business for increased sales and enhanced shopping experiences at no extra costs.
WCBoost – Wishlist
wcboost-wishlist
WCBoost - Wishlist lets shoppers create wishlists for later purchases, reminding them of desired items, driving repeat visits and boost sales.
Ecwid by Lightspeed Ecommerce Shopping Cart
ecwid-shopping-cart
Powerful, easy to use ecommerce shopping cart for WordPress. Sell on Facebook and Instagram. iPhone & Android apps. Superb support.
Welcart e-Commerce
usc-e-shop
Welcart is a free e-commerce plugin for Wordpress with top market share in Japan.
All Countries Counties For WooCommerce Developer Profile
1 plugin · 30 total installs
How We Detect All Countries Counties For WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/all-countries-counties-for-wc/js/wc-add-local-government-field.js/wp-content/plugins/all-countries-counties-for-wc/js/wc-add-local-government-field.jsall-countries-counties-for-wc/js/wc-add-local-government-field.js?ver=HTML / DOM Fingerprints
woocommerce-billing-fields__field-wrapperwoocommerce-shipping-fields__field-wrappername="billing_local_government"name="shipping_local_government"