
DCO Address Field for Contact Form 7 Security & Risk Analysis
wordpress.org/plugins/dco-address-field-for-contact-form-7Adds a autocomplete suggestion address field for Contact Form 7
Is DCO Address Field for Contact Form 7 Safe to Use in 2026?
Generally Safe
Score 85/100DCO Address Field for Contact Form 7 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The static analysis of the "dco-address-field-for-contact-form-7" plugin v1.1 indicates a strong security posture in several key areas. The absence of any identified dangerous functions, raw SQL queries, file operations, or external HTTP requests is commendable. Furthermore, the high percentage of properly escaped output suggests good practices in preventing cross-site scripting (XSS) vulnerabilities. The lack of any recorded vulnerabilities in its history also points to a well-maintained and secure plugin.
However, a significant concern arises from the complete absence of nonce checks and capability checks across all identified entry points, even though the attack surface is currently reported as zero. This implies that if any entry points were to be introduced or discovered in future versions, they would likely be unprotected, leaving the plugin vulnerable to various attacks such as cross-site request forgery (CSRF) or unauthorized access. The reported zero taint flows with unsanitized paths is positive, but this is based on a dataset of zero analyzed flows, which offers limited assurance.
In conclusion, while the current version of the plugin exhibits excellent security practices in its existing code and a clean vulnerability history, the lack of inherent security controls like nonces and capability checks represents a critical weakness. This oversight means that any expansion of the plugin's functionality or unforeseen entry points could lead to severe security vulnerabilities. The plugin's strength lies in its current minimal codebase and output escaping, but its weakness is the potential for future insecurity due to the absence of foundational security checks.
Key Concerns
- Missing nonce checks on all entry points
- Missing capability checks on all entry points
- Taint analysis performed on 0 flows
DCO Address Field for Contact Form 7 Security Vulnerabilities
DCO Address Field for Contact Form 7 Code Analysis
Output Escaping
DCO Address Field for Contact Form 7 Attack Surface
WordPress Hooks 9
Maintenance & Trust
DCO Address Field for Contact Form 7 Maintenance & Trust
Maintenance Signals
Community Trust
DCO Address Field for Contact Form 7 Alternatives
Autocomplete for Calculated Fields Form
autocomplete-for-calculated-fields-form
Suggests words and phrases to auto-complete text field values as the user types.
Checkout Address Suggestion And Autocomplete For Woocommerce
checkout-address-suggestion-and-autocomplete-for-woocommerce
Allows your customers to Autocomplete billing and shipping address in checkout page with google places API.
SearchPlus
searchplus
Upgrades you search box to a fast and modern navigation utility.
HeyDay – Search More
heyday-search
Boost engagement and conversions by keeping users on your site with HeyDay Search More’s enhanced search suggestions and real-time product discovery.
USDigiTarget | Autocomplete Address For WooCommerce
usdigitarget-autocomplete-address-for-woocommerce
Enhance your WooCommerce checkout experience with USDigiTarget's address autocomplete plugin, powered by Google Maps API.
DCO Address Field for Contact Form 7 Developer Profile
5 plugins · 13K total installs
How We Detect DCO Address Field for Contact Form 7
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/dco-address-field-for-contact-form-7/dco-address-field-for-contact-form-7.js//api-maps.yandex.ru/2.1/?lang=//maps.googleapis.com/maps/api/js?libraries=places&key=HTML / DOM Fingerprints
wpcf7-form-control-wrapdco-address-field-cf7<!-- DCO Address Yandex --><!-- DCO Address Google -->data-search-restrictiondco_af_cf7<span class="wpcf7-form-control-wrap %1$s"><input %2$s />%3$s</span>