Datamap Address for Woocommerce Security & Risk Analysis

wordpress.org/plugins/datamap-address-for-woo

Този модул за WooCommerce добавя интелигентна функционалност за автоматично разпознаване и потвърждение на адреси при финализиране на поръчката.

0 active installs v1.2 PHP 8.1+ WP 5.0+ Updated Aug 3, 2025
address%d0%b0%d0%b4%d1%80%d0%b5%d1%81%d0%b4%d0%be%d1%81%d1%82%d0%b0%d0%b2%d0%ba%d0%b0%d0%bf%d1%80%d0%be%d0%b2%d0%b5%d1%80%d0%ba%d0%b0woocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Datamap Address for Woocommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Datamap Address for Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8mo ago
Risk Assessment

The 'datamap-address-for-woo' plugin v1.2 exhibits a mixed security posture. On the positive side, it demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping all output. The absence of any recorded vulnerabilities in its history, including critical or high severity ones, further suggests a history of relatively secure development. There are also no dangerous functions or file operations identified in the static analysis, and no taint flows with unsanitized paths were detected.

However, a significant concern arises from the presence of two unprotected AJAX handlers, which represent a substantial attack surface. While the plugin has a limited number of entry points, these unprotected handlers could potentially be exploited by unauthenticated users. The static analysis also indicates a lack of capability checks, which should ideally be implemented for sensitive AJAX actions to ensure proper authorization. The plugin also makes external HTTP requests, which, while not inherently a vulnerability, can introduce risks if not handled securely (e.g., potential for SSRF or data leakage if endpoints are not validated or trusted).

Overall, the plugin's strong adherence to secure coding practices in critical areas like SQL and output handling is commendable. The lack of past vulnerabilities is a positive indicator. Nevertheless, the unprotected AJAX endpoints present a clear and present risk that needs immediate attention. Addressing these unprotected handlers and implementing proper authorization checks would significantly improve the plugin's security.

Key Concerns

  • Unprotected AJAX handlers found
  • No capability checks found
Vulnerabilities
None known

Datamap Address for Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Datamap Address for Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
19 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
0

Output Escaping

100% escaped19 total outputs
Attack Surface
2 unprotected

Datamap Address for Woocommerce Attack Surface

Entry Points4
Unprotected2

AJAX Handlers 4

authwp_ajax_dmaw_datamap_address_woo_submitAjaxajax-handler.php:41
noprivwp_ajax_dmaw_datamap_address_woo_submitAjaxajax-handler.php:42
authwp_ajax_save_custom_field_to_customerdatamap-address-for-woo.php:346
noprivwp_ajax_save_custom_field_to_customerdatamap-address-for-woo.php:347
WordPress Hooks 18
filterwoocommerce_settings_tabs_arrayadmin-settings.php:11
actionwoocommerce_settings_tabs_dmaw_datamap_address_wooadmin-settings.php:18
actionwoocommerce_update_options_dmaw_datamap_address_wooadmin-settings.php:25
filterwoocommerce_admin_settings_sanitize_optionadmin-settings.php:155
filteroption_dmaw_datamap_address_woo_api_passwordadmin-settings.php:158
actionadmin_enqueue_scriptsadmin-settings.php:163
actioninitdatamap-address-for-woo.php:30
actioninitdatamap-address-for-woo.php:43
actionwp_enqueue_scriptsdatamap-address-for-woo.php:55
actionwp_enqueue_scriptsdatamap-address-for-woo.php:111
actionwoocommerce_initdatamap-address-for-woo.php:144
actionwoocommerce_sanitize_additional_fielddatamap-address-for-woo.php:159
actionwoocommerce_store_api_checkout_update_order_from_requestdatamap-address-for-woo.php:172
filterwoocommerce_order_get_formatted_shipping_addressdatamap-address-for-woo.php:190
actionwoocommerce_after_checkout_billing_formdatamap-address-for-woo.php:235
actionwoocommerce_after_checkout_shipping_formdatamap-address-for-woo.php:261
actionwoocommerce_checkout_processdatamap-address-for-woo.php:284
actionwoocommerce_checkout_create_orderdatamap-address-for-woo.php:305
Maintenance & Trust

Datamap Address for Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 3, 2025
PHP min version8.1
Downloads310

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Datamap Address for Woocommerce Developer Profile

datamap

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Datamap Address for Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/datamap-address-for-woo/assets/jquery-ui.css/wp-content/plugins/datamap-address-for-woo/assets/style.css/wp-content/plugins/datamap-address-for-woo/assets/script.js
Script Paths
/wp-content/plugins/datamap-address-for-woo/assets/script.js
Version Parameters
datamap-address-for-woo/assets/style.css?ver=datamap-address-for-woo/assets/script.js?ver=

HTML / DOM Fingerprints

Data Attributes
dmaw_datamap_address_woo/dcode
JS Globals
dmaw_api_connectdmaw_settings
FAQ

Frequently Asked Questions about Datamap Address for Woocommerce