Address Autocomplete via Google for Gravity Forms Security & Risk Analysis

wordpress.org/plugins/gf-google-address-autocomplete

A simple and nice plugin to get auto suggestion from google place api in gravity form address field.

2K active installs v1.3.6 PHP 5.6+ WP 5.0+ Updated Aug 25, 2025
addressautocompletegeolocationgoogle-place-apigravityforms
99
A · Safe
CVEs total1
Unpatched0
Last CVEJun 27, 2025
Download
Safety Verdict

Is Address Autocomplete via Google for Gravity Forms Safe to Use in 2026?

Generally Safe

Score 99/100

Address Autocomplete via Google for Gravity Forms has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Jun 27, 2025Updated 7mo ago
Risk Assessment

The plugin "gf-google-address-autocomplete" v1.3.6 exhibits a generally strong security posture based on the static analysis. The absence of dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, and a clean taint analysis indicate that the core code is well-written and resistant to common vulnerabilities. The plugin also adheres to good practices by not exposing a large attack surface through AJAX handlers, REST API routes, shortcodes, or cron events without proper checks.

However, the plugin's vulnerability history presents a notable concern. It has a recorded CVE, specifically a medium-severity Cross-Site Request Forgery (CSRF) vulnerability, which was last patched on June 27, 2025. While currently unpatched CVEs are zero, the existence of a past CSRF vulnerability, even if patched, suggests a potential area of weakness. The lack of nonce checks in the static analysis could be a contributing factor to such vulnerabilities, as it indicates a reliance on other mechanisms or assumptions for security, which can be brittle.

In conclusion, while the static code analysis is impressive and points to robust development practices, the historical vulnerability data, particularly the CSRF issue, warrants a cautious approach. Developers should ensure that all entry points, even those not immediately apparent in the static analysis, are protected against CSRF attacks and that ongoing security monitoring remains a priority.

Key Concerns

  • Past medium-severity CVE (CSRF)
  • Zero nonce checks detected
Vulnerabilities
1

Address Autocomplete via Google for Gravity Forms Security Vulnerabilities

CVEs by Year

1 CVE in 2025
2025
Patched Has unpatched

Severity Breakdown

Medium
1

1 total CVE

CVE-2025-53263medium · 4.3Cross-Site Request Forgery (CSRF)

Address Autocomplete via Google for Gravity Forms <= 1.3.4 - Cross-Site Request Forgery

Jun 27, 2025 Patched in 1.3.5 (22d)
Code Analysis
Analyzed Mar 16, 2026

Address Autocomplete via Google for Gravity Forms Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
4 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped4 total outputs
Attack Surface

Address Autocomplete via Google for Gravity Forms Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 6
filtergform_tooltipsclass-auto-address-complete.php:38
actiongform_editor_jsclass-auto-address-complete.php:39
filtergform_register_init_scriptsclass-auto-address-complete.php:40
filtergform_field_settings_tabsclass-auto-address-complete.php:42
actiongform_field_settings_tab_content_address_auto_completeclass-auto-address-complete.php:43
actiongform_loadedgf-auto-address-complete.php:20
Maintenance & Trust

Address Autocomplete via Google for Gravity Forms Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedAug 25, 2025
PHP min version5.6
Downloads27K

Community Trust

Rating94/100
Number of ratings7
Active installs2K
Developer Profile

Address Autocomplete via Google for Gravity Forms Developer Profile

PluginsCafe

16 plugins · 11K total installs

92
trust score
Avg Security Score
97/100
Avg Patch Time
24 days
View full developer profile
Detection Fingerprints

How We Detect Address Autocomplete via Google for Gravity Forms

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/gf-google-address-autocomplete/assets/css/gf-auto-address-complete.css/wp-content/plugins/gf-google-address-autocomplete/assets/js/gf-auto-address-complete.js
Script Paths
/wp-content/plugins/gf-google-address-autocomplete/assets/js/gf-auto-address-complete.js
Version Parameters
/wp-content/plugins/gf-google-address-autocomplete/assets/css/gf-auto-address-complete.css?ver=/wp-content/plugins/gf-google-address-autocomplete/assets/js/gf-auto-address-complete.js?ver=

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about Address Autocomplete via Google for Gravity Forms