DCO Address Field for Contact Form 7 Security & Risk Analysis

wordpress.org/plugins/dco-address-field-for-contact-form-7

Adds a autocomplete suggestion address field for Contact Form 7

100 active installs v1.1 PHP + WP 4.7+ Updated Apr 5, 2018
address-fieldaddress-suggestion-contact-form-7autocompletesuggestsuggestion
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is DCO Address Field for Contact Form 7 Safe to Use in 2026?

Generally Safe

Score 85/100

DCO Address Field for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 8yr ago
Risk Assessment

The static analysis of the "dco-address-field-for-contact-form-7" plugin v1.1 indicates a strong security posture in several key areas. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is commendable. Furthermore, the high percentage of properly escaped output suggests good practices in preventing cross-site scripting (XSS) vulnerabilities. The lack of any recorded vulnerabilities in its history also points to a well-maintained and secure plugin.

However, a significant concern arises from the complete absence of nonce checks and capability checks across all identified entry points, even though the attack surface is currently reported as zero. This implies that if any entry points were to be introduced or discovered in future versions, they would likely be unprotected, leaving the plugin vulnerable to various attacks such as cross-site request forgery (CSRF) or unauthorized access. The reported zero taint flows with unsanitized paths is positive, but this is based on a dataset of zero analyzed flows, which offers limited assurance.

In conclusion, while the current version of the plugin exhibits excellent security practices in its existing code and a clean vulnerability history, the lack of inherent security controls like nonces and capability checks represents a critical weakness. This oversight means that any expansion of the plugin's functionality or unforeseen entry points could lead to severe security vulnerabilities. The plugin's strength lies in its current minimal codebase and output escaping, but its weakness is the potential for future insecurity due to the absence of foundational security checks.

Key Concerns

  • Missing nonce checks on all entry points
  • Missing capability checks on all entry points
  • Taint analysis performed on 0 flows
Vulnerabilities
None known

DCO Address Field for Contact Form 7 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

DCO Address Field for Contact Form 7 Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
14
81 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

85% escaped95 total outputs
Attack Surface

DCO Address Field for Contact Form 7 Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 9
actionwpcf7_initaddress_field.php:4
filterwpcf7_validate_dco_addressaddress_field.php:153
filterwpcf7_validate_dco_address*address_field.php:154
filterwpcf7_validate_dco_address_gmapsaddress_field.php:155
filterwpcf7_validate_dco_address_gmaps*address_field.php:156
actionwpcf7_admin_initaddress_field.php:170
actionadmin_initadmin.php:4
actionadmin_menuadmin.php:56
actionwp_enqueue_scriptsdco-address-field-for-contact-form-7.php:42
Maintenance & Trust

DCO Address Field for Contact Form 7 Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedApr 5, 2018
PHP min version
Downloads4K

Community Trust

Rating100/100
Number of ratings1
Active installs100
Developer Profile

DCO Address Field for Contact Form 7 Developer Profile

Denis Yanchevskiy

5 plugins · 13K total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect DCO Address Field for Contact Form 7

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/dco-address-field-for-contact-form-7/dco-address-field-for-contact-form-7.js
Script Paths
//api-maps.yandex.ru/2.1/?lang=//maps.googleapis.com/maps/api/js?libraries=places&key=

HTML / DOM Fingerprints

CSS Classes
wpcf7-form-control-wrapdco-address-field-cf7
HTML Comments
<!-- DCO Address Yandex --><!-- DCO Address Google -->
Data Attributes
data-search-restriction
JS Globals
dco_af_cf7
Shortcode Output
<span class="wpcf7-form-control-wrap %1$s"><input %2$s />%3$s</span>
FAQ

Frequently Asked Questions about DCO Address Field for Contact Form 7