Crafty Clicks Postcode Lookup Security & Risk Analysis

wordpress.org/plugins/crafty-clicks-postcode-lookup

This plugin adds UK postcode lookup functionality to the address forms on the front-end in WooCommerce.

100 active installs v1.2.11 PHP + WP 4.0+ Updated Jan 13, 2020
addressaddressescheckoutdatafill
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Crafty Clicks Postcode Lookup Safe to Use in 2026?

Generally Safe

Score 85/100

Crafty Clicks Postcode Lookup has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 6yr ago
Risk Assessment

The crafty-clicks-postcode-lookup plugin exhibits an exceptionally strong security posture based on the provided static analysis and vulnerability history. The absence of any identified dangerous functions, raw SQL queries, unescaped output, or file operations is a significant positive. Furthermore, the complete lack of known CVEs, both historical and currently unpatched, suggests a well-maintained and secure codebase. The zero-count for AJAX handlers, REST API routes, shortcodes, and cron events also indicates a minimal attack surface, which is ideal for security.

While the analysis reveals no critical or high-severity issues in taint flows, the absence of any identified flows at all means that any potential weaknesses in sanitization or validation within the code might have been missed. This is a theoretical concern given the otherwise clean analysis. However, the plugin's documented history of zero vulnerabilities across all severities and types strongly indicates a robust development and testing process.

In conclusion, the plugin demonstrates excellent security practices. The lack of identified vulnerabilities and the clean code signals are highly reassuring. The only minor point of consideration is the lack of any taint flow analysis results, which could imply that complex or subtle vulnerabilities might not have been detected if they existed. Nevertheless, the overall picture is one of a highly secure and reliable plugin.

Vulnerabilities
None known

Crafty Clicks Postcode Lookup Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Crafty Clicks Postcode Lookup Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
0 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0
Attack Surface

Crafty Clicks Postcode Lookup Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionplugins_loadedcraftyclicks_postcode_lookup.php:39
filterwoocommerce_integrationscraftyclicks_postcode_lookup.php:52
actionwoocommerce_checkout_billingincludes\class-wc-craftyclicks-postcode-lookup-integration.php:50
actionwoocommerce_before_edit_account_address_formincludes\class-wc-craftyclicks-postcode-lookup-integration.php:51
actionedit_user_profileincludes\class-wc-craftyclicks-postcode-lookup-integration.php:54
actionprofile_personal_optionsincludes\class-wc-craftyclicks-postcode-lookup-integration.php:55
actiondbx_post_advancedincludes\class-wc-craftyclicks-postcode-lookup-integration.php:58
filterwoocommerce_integrationswp\menu.php:4
actionadmin_noticeswp\menu.php:6
Maintenance & Trust

Crafty Clicks Postcode Lookup Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedJan 13, 2020
PHP min version
Downloads5K

Community Trust

Rating100/100
Number of ratings3
Active installs100
Developer Profile

Crafty Clicks Postcode Lookup Developer Profile

Fetchify

2 plugins · 800 total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Crafty Clicks Postcode Lookup

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/crafty-clicks-postcode-lookup/js/checkout.js/wp-content/plugins/crafty-clicks-postcode-lookup/js/users.js/wp-content/plugins/crafty-clicks-postcode-lookup/js/orders.js
Script Paths
/wp-content/plugins/crafty-clicks-postcode-lookup/js/checkout.js/wp-content/plugins/crafty-clicks-postcode-lookup/js/users.js/wp-content/plugins/crafty-clicks-postcode-lookup/js/orders.js

HTML / DOM Fingerprints

JS Globals
window._cp_configwindow._cp_busy_img_url
FAQ

Frequently Asked Questions about Crafty Clicks Postcode Lookup