
Courier Address Security & Risk Analysis
wordpress.org/plugins/courier-address[courier_address] Google address Autocomplete, [courier_distance] Google Map, [courier_result] price from configurable equation.
Is Courier Address Safe to Use in 2026?
Generally Safe
Score 85/100Courier Address has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'courier-address' plugin version 3.2 presents a mixed security posture. On the positive side, it demonstrates good practices by avoiding dangerous functions, using prepared statements for all SQL queries, and having no known historical CVEs, which suggests a generally well-maintained codebase. The absence of external HTTP requests and bundled libraries further reduces potential attack vectors. However, significant concerns arise from the static analysis. A notable weakness is the lack of proper output escaping, with only 15% of identified outputs being correctly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not sufficiently sanitized before being displayed to other users. Additionally, while the plugin has no unprotected entry points directly exposed by AJAX handlers or REST API routes, the presence of six shortcodes and a flow with unsanitized paths in the taint analysis warrants attention, as these could still be vectors for manipulation if not handled with care.
Key Concerns
- Low output escaping percentage
- Unsanitized path in taint flow
- No nonce checks on entry points
- No capability checks on entry points
Courier Address Security Vulnerabilities
Courier Address Release Timeline
Courier Address Code Analysis
Output Escaping
Data Flow Analysis
Courier Address Attack Surface
Shortcodes 6
WordPress Hooks 10
Maintenance & Trust
Courier Address Maintenance & Trust
Maintenance Signals
Community Trust
Courier Address Alternatives
Map Field for Contact Form 7
map-field-for-contact-form-7
Add a Google Maps autocomplete address field with a live interactive map to any Contact Form 7 form. Supports draggable marker, address components, an …
DCO Address Field for Contact Form 7
dco-address-field-for-contact-form-7
Adds a autocomplete suggestion address field for Contact Form 7
Conditional Fields for Contact Form 7
cf7-conditional-fields
Adds conditional logic to Contact Form 7.
Contact Form 7 – Dynamic Text Extension
contact-form-7-dynamic-text-extension
Extends Contact Form 7 by adding dynamic form fields that accepts shortcodes to prepopulate form fields with default values and dynamic placeholders.
Country & Phone Field Contact Form 7
country-phone-field-contact-form-7
Add country drop down with flags and phone number with country phone extension fields in contact form 7.
Courier Address Developer Profile
3 plugins · 20 total installs
How We Detect Courier Address
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/courier-address/css/courier-address.css/wp-content/plugins/courier-address/js/courier-address.js/wp-content/plugins/courier-address/js/courier-address.jscourier-address/css/courier-address.css?ver=courier-address/js/courier-address.js?ver=HTML / DOM Fingerprints
courier_address_postcode_groupcourier_address_postcode_group_pricecourier_address_plugin_page[courier_address[courier_distance[courier_result