
Autocomplete for Calculated Fields Form Security & Risk Analysis
wordpress.org/plugins/autocomplete-for-calculated-fields-formSuggests words and phrases to auto-complete text field values as the user types.
Is Autocomplete for Calculated Fields Form Safe to Use in 2026?
Generally Safe
Score 100/100Autocomplete for Calculated Fields Form has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin "autocomplete-for-calculated-fields-form" v1.1.0 presents a generally good security posture based on the provided static analysis. The absence of any identified CVEs, coupled with strong practices like 100% use of prepared statements for SQL queries and the presence of nonce and capability checks, suggests a developer attentive to common WordPress security pitfalls. The limited attack surface with zero AJAX handlers, REST API routes, shortcodes, or cron events is a significant strength, reducing the potential for exploitation.
However, a few areas warrant attention. The analysis indicates two flows with unsanitized paths, which, while not classified as critical or high severity in the taint analysis, represent potential weaknesses. These flows could theoretically lead to issues if they interact with sensitive functionalities or external resources, even if currently benign. Furthermore, 100% output escaping is not achieved, with one out of six outputs not properly escaped. This single unescaped output, while seemingly minor, could still be a vector for cross-site scripting (XSS) vulnerabilities, especially if the data originates from user input and is rendered without sanitization.
The vulnerability history being completely clean is a very positive sign, implying a history of secure development. The plugin's strengths lie in its minimal attack surface and robust handling of core WordPress security features. The weaknesses, though not critical, are primarily in the potential for path traversal given the unsanitized paths and the minor output escaping deficiency. Addressing these would further solidify the plugin's security.
Key Concerns
- Flows with unsanitized paths (2)
- Unescaped output (1 of 6)
Autocomplete for Calculated Fields Form Security Vulnerabilities
Autocomplete for Calculated Fields Form Code Analysis
Output Escaping
Data Flow Analysis
Autocomplete for Calculated Fields Form Attack Surface
WordPress Hooks 5
Maintenance & Trust
Autocomplete for Calculated Fields Form Maintenance & Trust
Maintenance Signals
Community Trust
Autocomplete for Calculated Fields Form Alternatives
AI Powered Marketing
kliken-marketing-for-google
Kliken's all-in-one marketing helps businesses reach high-intent customers, beat the competition and see sales growth while lowering conversion costs
Autocomplete WooCommerce Orders
autocomplete-woocommerce-orders
Enhance your WooCommerce store with Autocomplete Orders. Automatically complete orders after payment, perfect for virtual goods and subscriptions.
WP Console – WordPress PHP Console powered by PsySH
wp-console
An in-browser PHP console for WordPress powered by PsySH
CallRail Phone Call Tracking
callrail-phone-call-tracking
Dynamically swap CallRail tracking phone numbers based on the visitor's referring source.
Simple SEO
cds-simple-seo
Allows the modification of META titles, descriptions and keywords for all pages and posts. Also allows for default setting for of META title, descript …
Autocomplete for Calculated Fields Form Developer Profile
34 plugins · 89K total installs
How We Detect Autocomplete for Calculated Fields Form
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/autocomplete-for-calculated-fields-form/assets/admin.js/wp-content/plugins/autocomplete-for-calculated-fields-form/assets/public.js/wp-content/plugins/autocomplete-for-calculated-fields-form/assets/public.jsautocomplete-for-calculated-fields-form/assets/public.js?ver=HTML / DOM Fingerprints
cff-installation-banner-picturecff-installation-banner-contentcff-installation-banner-textcff-installation-banner-buttonsid="cff-installation-banner"cff_autocomplete_settings