
Autocomplete Address and Location Picker for WooCommerce Security & Risk Analysis
wordpress.org/plugins/autocomplete-address-and-location-picker-for-woocommerceImprove your WooCommerce checkout flow with Google Places address autocomplete, geocoding, and location picker tools. Supports Classic Checkout and Ch …
Is Autocomplete Address and Location Picker for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Autocomplete Address and Location Picker for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'autocomplete-address-and-location-picker-for-woocommerce' version 1.2.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries, has a history free of recorded vulnerabilities, and avoids dangerous functions, file operations, and external HTTP requests. The presence of a nonce check and a high percentage of properly escaped output are also commendable. However, significant concerns arise from its attack surface. With two AJAX handlers identified, both lacking authentication checks, this presents a considerable risk. These unprotected entry points could be exploited by unauthenticated users to trigger plugin functionality, potentially leading to unintended consequences or enabling further attacks if flaws exist within the handler's logic.
The static analysis reveals two AJAX handlers that do not have authentication checks. This is the primary security concern identified in the code. Taint analysis did not uncover any critical or high severity flows, suggesting that data flowing into these handlers is not being immediately misused in a critical way. However, the absence of authentication on these handlers means an attacker can freely interact with them. The plugin's vulnerability history is clean, which is a strong positive indicator of its general security quality and the development team's attention to security. Despite the clean history, the unprotected AJAX endpoints remain a notable weakness that should be addressed.
Key Concerns
- AJAX handlers without auth checks
- Capability checks missing on AJAX handlers
- Bundled outdated Freemius library (v1.0)
Autocomplete Address and Location Picker for WooCommerce Security Vulnerabilities
Autocomplete Address and Location Picker for WooCommerce Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Autocomplete Address and Location Picker for WooCommerce Attack Surface
AJAX Handlers 2
WordPress Hooks 16
Maintenance & Trust
Autocomplete Address and Location Picker for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Autocomplete Address and Location Picker for WooCommerce Alternatives
Kikote – Location Picker at Checkout & Google Address AutoFill Plugin for WooCommerce
map-location-picker-at-checkout-for-woocommerce
Allow customers to select delivery/pickup spots on Google Maps at Checkout. Create shipping workflows for smooth order handling and better pricing.
Checkout Location Picker for WooCommerce
sg-checkout-location-picker
Sg WooCommerce Checkout Location Picker helps customers to mark their geo location on google map in WooCommerce checkout page.
Checkout Field Editor (Checkout Manager) for WooCommerce
woo-checkout-field-editor-pro
Checkout Field Editor (Checkout Manager) for WooCommerce – The best WooCommerce checkout manager plugin to manage WooCommerce checkout fields.
Checkout Field Manager (Checkout Manager) for WooCommerce
woocommerce-checkout-manager
Checkout Field Manager (Checkout Manager) for WooCommerce is the most advanced plugin to customize checkout fields on your WooCommerce checkout page.
Flexible Checkout Fields for WooCommerce – WooCommerce Checkout Manager
flexible-checkout-fields
The best WooCommerce checkout manager. Edit, remove or add checkout fields. Customize WooCommerce checkout with this checkout field customizer.
Autocomplete Address and Location Picker for WooCommerce Developer Profile
8 plugins · 3K total installs
How We Detect Autocomplete Address and Location Picker for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/autocomplete-address-and-location-picker-for-woocommerce/assets/css/aafw-admin.css/wp-content/plugins/autocomplete-address-and-location-picker-for-woocommerce/assets/css/aafw-frontend.css/wp-content/plugins/autocomplete-address-and-location-picker-for-woocommerce/assets/js/aafw-admin.js/wp-content/plugins/autocomplete-address-and-location-picker-for-woocommerce/assets/js/aafw-frontend.jsautocomplete-address-and-location-picker-for-woocommerce/assets/css/aafw-admin.css?ver=autocomplete-address-and-location-picker-for-woocommerce/assets/css/aafw-frontend.css?ver=autocomplete-address-and-location-picker-for-woocommerce/assets/js/aafw-admin.js?ver=autocomplete-address-and-location-picker-for-woocommerce/assets/js/aafw-frontend.js?ver=HTML / DOM Fingerprints
aafw_admin_section_titleaafw_section_titledata-aafw_google_api_keydata-aafw_placeholderdata-aafw_location_typesdata-aafw_restrict_by_countrydata-aafw_country_restrictiondata-aafw_disable_all_fieldsaafw_frontend_object