
AutoCEP Security & Risk Analysis
wordpress.org/plugins/autocepO plugin AutoCEP preenche automaticamente os campos de endereço no checkout com base no CEP digitado pelo usuário.
Is AutoCEP Safe to Use in 2026?
Generally Safe
Score 100/100AutoCEP has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "autocep" v1.5 plugin demonstrates several good security practices, particularly in its use of prepared statements for SQL queries and proper output escaping, indicating an awareness of common web application vulnerabilities. The absence of known CVEs and taint analysis findings further contributes to a generally positive security posture. The plugin also utilizes a nonce check, which is a fundamental security measure for handling user interactions.
However, a significant concern arises from the presence of two AJAX handlers, both of which lack authentication checks. This creates an exposed attack surface where unauthenticated users could potentially trigger actions within the plugin, leading to unintended consequences. While the static analysis did not reveal specific dangerous functions or file operations, the lack of capability checks on these AJAX endpoints is a critical oversight. The plugin's vulnerability history shows no recorded issues, suggesting a good track record or a lack of extensive past security audits. Ultimately, while the plugin implements some important security controls, the unprotected AJAX endpoints represent a substantial risk that needs immediate attention.
Key Concerns
- AJAX handlers without authentication checks
- Lack of capability checks on entry points
AutoCEP Security Vulnerabilities
AutoCEP Code Analysis
Output Escaping
AutoCEP Attack Surface
AJAX Handlers 2
WordPress Hooks 1
Maintenance & Trust
AutoCEP Maintenance & Trust
Maintenance Signals
Community Trust
AutoCEP Alternatives
Autocomplete Address for WooCommerce
autocomplete-address-for-woocommerce
Preencha automaticamente o endereço a partir do CEP no WooCommerce
Autocomplete Address and Location Picker for WooCommerce
autocomplete-address-and-location-picker-for-woocommerce
Improve your WooCommerce checkout flow with Google Places address autocomplete, geocoding, and location picker tools. Supports Classic Checkout and Ch …
Preenche endereço CEP para Woocommerce
preenche-endereco-cep
Preenchimento automático de campos de endereço baseado no CEP informado.
FPG – Endereço automático por Cep no Checkout
fpg-endereco-automatico-por-cep-no-checkout
Preenche o endereço, no checkout, automáticamente através do cep.
Checkout Address AutoFill For WooCommerce
checkout-address-autofill-for-woocommerce
Checkout Address AutoFill For WooCommerce is a WooCommerce add-on which allows your user to autofill both Billing and Shipping address fields in the c …
AutoCEP Developer Profile
1 plugin · 1K total installs
How We Detect AutoCEP
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/autocep/js/autocomplete.js/wp-content/plugins/autocep/js/autocomplete.jsautocep-autocomplete?ver=HTML / DOM Fingerprints
autocep_params