
Autocomplete Google places Security & Risk Analysis
wordpress.org/plugins/autocomplete-google-placesThis plugin will help you to use Place Autocomplete API key.
Is Autocomplete Google places Safe to Use in 2026?
Generally Safe
Score 85/100Autocomplete Google places has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'autocomplete-google-places' v1.4.0 plugin exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, unpatched vulnerabilities, or critical/high severity issues in its history is a strong positive indicator. Furthermore, the code analysis reveals no dangerous functions, no raw SQL queries, and no external HTTP requests, all of which are excellent security practices.
However, there are areas that warrant attention. While the attack surface is small with only two AJAX handlers, the fact that none of them are explicitly noted as having authentication checks (though this could be implied by the 'Unprotected: 0' entry, it's not explicitly stated) could represent a potential risk if these handlers perform sensitive operations. The output escaping, while at 74%, is not perfect, leaving a portion of outputs potentially vulnerable to cross-site scripting (XSS) if user-supplied data is involved in those unescaped outputs. The lack of taint analysis data is also a slight concern, as it means certain types of vulnerabilities might have been missed.
In conclusion, the plugin appears to be reasonably secure, with a clean historical record and several strong security implementations. The primary areas for improvement lie in ensuring robust authentication for AJAX handlers and further refining output escaping to achieve 100% proper escaping to mitigate any potential XSS risks. The absence of taint analysis could also be addressed in future reviews.
Key Concerns
- AJAX handlers without explicit auth checks noted
- Output escaping not 100% proper
Autocomplete Google places Security Vulnerabilities
Autocomplete Google places Release Timeline
Autocomplete Google places Code Analysis
Output Escaping
Autocomplete Google places Attack Surface
AJAX Handlers 2
WordPress Hooks 50
Maintenance & Trust
Autocomplete Google places Maintenance & Trust
Maintenance Signals
Community Trust
Autocomplete Google places Alternatives
Autocomplete Google Address
autocomplete-google-address
The #1 Google Address Autocomplete for WordPress. Visual point-and-click setup -- no coding needed. Works with WooCommerce, CF7, WPForms, Gravity Form …
Autocomplete Location Field for Contact Form 7
autocomplete-location-field-contact-form-7
Add Google Places Autocomplete address field to Contact Form 7. Enable automatic address suggestions using Google Maps API for faster and more accurat …
Checkout Address AutoFill For WooCommerce
checkout-address-autofill-for-woocommerce
Checkout Address AutoFill For WooCommerce is a WooCommerce add-on which allows your user to autofill both Billing and Shipping address fields in the c …
Simple Address Autocomplete
simple-address-autocomplete
A simple way to add Google address autocomplete functionality to any form in WordPress. Limit the search to one country or worldwide.
Autofilll HKGov Address For WC
wc-hkgov-address-autofill
Search and autofill the checkout form with Hong Kong Gov address or Google Place API.
Autocomplete Google places Developer Profile
1 plugin · 40 total installs
How We Detect Autocomplete Google places
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/autocomplete-google-places/js/autocomplete.js/wp-content/plugins/autocomplete-google-places/js/contactf7.jshttps://maps.googleapis.com/maps/api/js?key=HTML / DOM Fingerprints
pac-containerpac-iteminput_fields