
Auto Populate Country/State/City/Ward DropDown Addon for Gravity Forms Security & Risk Analysis
wordpress.org/plugins/gf-auto-populate-country-state-city-ward-dropdown-addonAUTO POPULATE COUNTRY/STATE/CITY/WARD GRAVITYFORMS ADDON
Is Auto Populate Country/State/City/Ward DropDown Addon for Gravity Forms Safe to Use in 2026?
Generally Safe
Score 85/100Auto Populate Country/State/City/Ward DropDown Addon for Gravity Forms has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "gf-auto-populate-country-state-city-ward-dropdown-addon" plugin v1.1 exhibits a concerning security posture due to a significant attack surface composed of six AJAX handlers, all of which lack authentication checks. This means any unauthenticated user could potentially trigger these handlers, leading to unintended actions or data exposure if the underlying functionality is not properly secured. While the plugin shows promise by not using dangerous functions and utilizing prepared statements for its SQL queries, the absence of capability checks and nonce verification on its AJAX endpoints creates a clear vulnerability. The analysis also indicates that only 45% of its output is properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not sanitized before being displayed.
The vulnerability history is notably clean, with no recorded CVEs. This, combined with the absence of critical or high-severity taint flows, suggests that while the plugin might have potential weaknesses, they haven't yet manifested in publicly known exploits or been identified through static taint analysis. However, this lack of history should not be interpreted as a sign of robust security, especially given the identified attack surface and output escaping issues. The plugin demonstrates some good practices regarding SQL and dangerous functions, but the significant lack of authorization and proper output handling on its entry points presents a substantial risk that needs immediate attention.
Key Concerns
- AJAX handlers without auth checks
- Insufficient output escaping (55% unescaped)
- No nonce checks on AJAX handlers
- No capability checks on AJAX handlers
Auto Populate Country/State/City/Ward DropDown Addon for Gravity Forms Security Vulnerabilities
Auto Populate Country/State/City/Ward DropDown Addon for Gravity Forms Code Analysis
Output Escaping
Auto Populate Country/State/City/Ward DropDown Addon for Gravity Forms Attack Surface
AJAX Handlers 6
WordPress Hooks 9
Maintenance & Trust
Auto Populate Country/State/City/Ward DropDown Addon for Gravity Forms Maintenance & Trust
Maintenance Signals
Community Trust
Auto Populate Country/State/City/Ward DropDown Addon for Gravity Forms Alternatives
Gravity Forms Zero Spam
gravity-forms-zero-spam
Enhance your Gravity Forms to include anti-spam measures originally based on the work of David Walsh's "Zero Spam" technique.
Gravity Booster – Styles & Layouts for Gravity Forms
styles-and-layouts-for-gravity-forms
Gravity Booster - Styles and Layouts for Gravity Forms plugin lets you design and style Gravity Forms without CSS coding. You can also use it for addi …
Advanced Custom Fields: Gravity Forms Add-on
acf-gravityforms-add-on
Provides an Advanced Custom Field which allows a WordPress user to select a Gravity Form as part of a field group configuration.
Event Tracking for Gravity Forms
gravity-forms-google-analytics-event-tracking
Easily add event tracking using Gravity Forms and your Google Analytics or Google Tag Manager account. Supports Google Analytics v3 and Gravity Forms …
Gravity PDF
gravity-forms-pdf-extended
Automatically generate, email and download PDF documents from Gravity Forms entries
Auto Populate Country/State/City/Ward DropDown Addon for Gravity Forms Developer Profile
4 plugins · 1K total installs
How We Detect Auto Populate Country/State/City/Ward DropDown Addon for Gravity Forms
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/gf-auto-populate-country-state-city-ward-dropdown-addon/css/admin.css/wp-content/plugins/gf-auto-populate-country-state-city-ward-dropdown-addon/css/font-end.css/wp-content/plugins/gf-auto-populate-country-state-city-ward-dropdown-addon/js/admin.js/wp-content/plugins/gf-auto-populate-country-state-city-ward-dropdown-addon/js/admin.jsgf-auto-populate-country-state-city-ward-dropdown-addon/css/admin.css?ver=gf-auto-populate-country-state-city-ward-dropdown-addon/css/font-end.css?ver=gf-auto-populate-country-state-city-ward-dropdown-addon/js/admin.js?ver=HTML / DOM Fingerprints
input_class_settingfield_default_valuecountrycityfield_default_valuemerge-tag-supportmt-position-rightmt-prepopulateajax_object