
Autocomplete Location Field for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/autocomplete-location-field-contact-form-7Add Google Places Autocomplete address field to Contact Form 7. Enable automatic address suggestions using Google Maps API for faster and more accurat …
Is Autocomplete Location Field for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 100/100Autocomplete Location Field for Contact Form 7 has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The "autocomplete-location-field-contact-form-7" plugin, version 4.0, presents a generally positive security posture based on the static analysis. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is commendable. Furthermore, the high percentage of properly escaped output (82%) indicates a good effort to prevent cross-site scripting (XSS) vulnerabilities. The plugin also has a clean taint analysis report with no unsanitized flows, suggesting that developer attention has been paid to secure input handling.
However, the plugin's vulnerability history is a significant concern. A single known CVE, although currently patched, points to past security weaknesses. The recurrence of 'Cross-site Scripting' as a common vulnerability type is particularly noteworthy, as it suggests that the developer may have struggled with thoroughly sanitizing all user inputs that could be rendered on a webpage. The lack of explicitly detailed capability checks and nonce checks in the static analysis, while not directly indicating a vulnerability, could potentially leave certain functionalities exposed if they were to interact with sensitive WordPress actions, though the current attack surface appears minimal.
In conclusion, while the current version (4.0) shows good development practices with regards to secure coding patterns like prepared statements and output escaping, the historical prevalence of XSS vulnerabilities warrants caution. The lack of a large attack surface is a strength, but the past vulnerabilities highlight a need for continued vigilance and thorough auditing of all input and output mechanisms in future releases. The absence of any active unpatched CVEs is a positive indicator of responsiveness to past issues.
Key Concerns
- Past XSS vulnerability history
- Missing nonce checks
- Missing capability checks
- Output escaping not 100%
Autocomplete Location Field for Contact Form 7 Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Autocomplete Location field Contact Form 7 <= 2.0 - Authenticated (Administrator+) Stored Cross-Site Scripting
Autocomplete Location Field for Contact Form 7 Release Timeline
Autocomplete Location Field for Contact Form 7 Code Analysis
Output Escaping
Autocomplete Location Field for Contact Form 7 Attack Surface
WordPress Hooks 17
Maintenance & Trust
Autocomplete Location Field for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
Autocomplete Location Field for Contact Form 7 Alternatives
Address autocomplete Contact Form 7
address-autocomplete-contact-form-7
Contact form 7 address autocomplete feature. We are using google maps api. https://maps.googleapis.com/maps/api
Checkout Address AutoFill For WooCommerce
checkout-address-autofill-for-woocommerce
Checkout Address AutoFill For WooCommerce is a WooCommerce add-on which allows your user to autofill both Billing and Shipping address fields in the c …
DS CF7 Math Captcha
ds-cf7-math-captcha
"DS CF7 Math Captcha" is a math captcha with refresh captcha functionality to prevent unwanted spam for your contact form 7 plugin.
Popups – Submission Messages For Contact Form 7
cf7-popups
Display contact form 7 default messages in stylish popup as user submits the form.
Autocomplete Google Address
autocomplete-google-address
The #1 Google Address Autocomplete for WordPress. Visual point-and-click setup -- no coding needed. Works with WooCommerce, CF7, WPForms, Gravity Form …
Autocomplete Location Field for Contact Form 7 Developer Profile
26 plugins · 12K total installs
How We Detect Autocomplete Location Field for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/autocomplete-location-field-contact-form-7/assents/css/style.css/autocomplete-location-field-contact-form-7/assents/css/style.css?ver=HTML / DOM Fingerprints
wpcf7-gmautocompletedata-initializedgoogleGWAA_cf7_geo_gpa_pagegwaa_country_codegwaa_place_typesgwaa_cf7_geo_api_key