Autocomplete Location Field for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/autocomplete-location-field-contact-form-7

Add Google Places Autocomplete address field to Contact Form 7. Enable automatic address suggestions using Google Maps API for faster and more accurat …

1K active installs v7.0 PHP 7.2+ WP 5.8+ Updated Mar 23, 2026
autocompletecheckout-address-autocompletecontact-form-7contact-form-7-addongoogle-address-autocomplete
100
A · Safe
CVEs total1
Unpatched0
Last CVENov 21, 2023
Download
Safety Verdict

Is Autocomplete Location Field for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 100/100

Autocomplete Location Field for Contact Form 7 has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.

1 known CVELast CVE: Nov 21, 2023Updated 1mo ago
Risk Assessment

The "autocomplete-location-field-contact-form-7" plugin, version 4.0, presents a generally positive security posture based on the static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is commendable. Furthermore, the high percentage of properly escaped output (82%) indicates a good effort to prevent cross-site scripting (XSS) vulnerabilities. The plugin also has a clean taint analysis report with no unsanitized flows, suggesting that developer attention has been paid to secure input handling.

However, the plugin's vulnerability history is a significant concern. A single known CVE, although currently patched, points to past security weaknesses. The recurrence of 'Cross-site Scripting' as a common vulnerability type is particularly noteworthy, as it suggests that the developer may have struggled with thoroughly sanitizing all user inputs that could be rendered on a webpage. The lack of explicitly detailed capability checks and nonce checks in the static analysis, while not directly indicating a vulnerability, could potentially leave certain functionalities exposed if they were to interact with sensitive WordPress actions, though the current attack surface appears minimal.

In conclusion, while the current version (4.0) shows good development practices with regards to secure coding patterns like prepared statements and output escaping, the historical prevalence of XSS vulnerabilities warrants caution. The lack of a large attack surface is a strength, but the past vulnerabilities highlight a need for continued vigilance and thorough auditing of all input and output mechanisms in future releases. The absence of any active unpatched CVEs is a positive indicator of responsiveness to past issues.

Key Concerns

  • Past XSS vulnerability history
  • Missing nonce checks
  • Missing capability checks
  • Output escaping not 100%
Vulnerabilities
1 published

Autocomplete Location Field for Contact Form 7 Security Vulnerabilities

CVEs by Year

1 CVE in 2023
2023
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2023-5005medium · 4.4Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Autocomplete Location field Contact Form 7 <= 2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting

Nov 21, 2023 Patched in 3.0 (63d)
Version History

Autocomplete Location Field for Contact Form 7 Release Timeline

No version history available.
Code Analysis
Analyzed Mar 16, 2026

Autocomplete Location Field for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
22
98 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

82% escaped120 total outputs
Attack Surface

Autocomplete Location Field for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 17
actionadmin_menuincludes\ACGWAA_Backend.php:9
actionadmin_initincludes\ACGWAA_Backend.php:10
actionwpcf7_initincludes\ACGWAA_Display.php:10
actionadmin_initincludes\ACGWAA_Display.php:11
actionwpcf7_validate_gmautocompleteincludes\ACGWAA_Display.php:12
actionwpcf7_validate_gmautocomplete*includes\ACGWAA_Display.php:13
filterwpcf7_special_mail_tagsincludes\ACGWAA_Display.php:15
actionwp_enqueue_scriptsincludes\ACGWAA_Frontend.php:11
actionwp_footerincludes\ACGWAA_Frontend.php:13
actionadmin_menuincludes\GWAA_Backend.php:9
actionadmin_initincludes\GWAA_Backend.php:10
actionwpcf7_initincludes\GWAA_Display.php:10
actionadmin_initincludes\GWAA_Display.php:11
actionwpcf7_validate_gmautocompleteincludes\GWAA_Display.php:12
actionwpcf7_validate_gmautocomplete*includes\GWAA_Display.php:13
actionwp_enqueue_scriptsincludes\GWAA_Frontend.php:11
actionwp_footerincludes\GWAA_Frontend.php:13
Maintenance & Trust

Autocomplete Location Field for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 23, 2026
PHP min version7.2
Downloads18K

Community Trust

Rating100/100
Number of ratings11
Active installs1K
Developer Profile

Autocomplete Location Field for Contact Form 7 Developer Profile

theme funda

26 plugins · 12K total installs

87
trust score
Avg Security Score
98/100
Avg Patch Time
85 days
View full developer profile
Detection Fingerprints

How We Detect Autocomplete Location Field for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/autocomplete-location-field-contact-form-7/assents/css/style.css
Version Parameters
/autocomplete-location-field-contact-form-7/assents/css/style.css?ver=

HTML / DOM Fingerprints

CSS Classes
wpcf7-gmautocomplete
Data Attributes
data-initialized
JS Globals
googleGWAA_cf7_geo_gpa_pagegwaa_country_codegwaa_place_typesgwaa_cf7_geo_api_key
FAQ

Frequently Asked Questions about Autocomplete Location Field for Contact Form 7