
Hide Address Fields for WooCommerce Security & Risk Analysis
wordpress.org/plugins/hide-address-fields-for-woocommerceWooCommerce plugin for hiding the billing address fields on checkout based on the selected shipping/payment methods.
Is Hide Address Fields for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Hide Address Fields for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'hide-address-fields-for-woocommerce' plugin, version 1.2.3, exhibits a mixed security posture. While it demonstrates good practices by not utilizing dangerous functions, performing all SQL queries with prepared statements, and having no known vulnerabilities or external HTTP requests, significant concerns arise from its attack surface. The presence of two AJAX handlers without authentication checks represents a notable risk, as these could potentially be exploited by unauthenticated users to manipulate plugin functionality. Furthermore, the lack of any nonce checks on these AJAX handlers exacerbates this risk, making cross-site request forgery (CSRF) attacks a possibility. The moderate rate of properly escaped output also suggests a potential for cross-site scripting (XSS) vulnerabilities, although this is not definitively confirmed by the provided data.
Despite the absence of critical taint flows and a clean vulnerability history, the unprotected entry points in the AJAX handlers are the most pressing security concerns. The lack of capability checks also means that even authenticated users might be able to perform actions they shouldn't, depending on the specific functionality of these AJAX handlers. In conclusion, the plugin has strengths in its handling of database operations and its clean historical record, but the unprotected AJAX endpoints and potential for unescaped output warrant careful attention and remediation to improve its overall security.
Key Concerns
- AJAX handlers without authentication checks
- AJAX handlers without nonce checks
- Low percentage of properly escaped output
- No capability checks on entry points
Hide Address Fields for WooCommerce Security Vulnerabilities
Hide Address Fields for WooCommerce Code Analysis
Output Escaping
Hide Address Fields for WooCommerce Attack Surface
AJAX Handlers 2
Shortcodes 1
WordPress Hooks 41
Maintenance & Trust
Hide Address Fields for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Hide Address Fields for WooCommerce Alternatives
Remove Checkout Fields for Woocommerce
remove-default-checkout-fields-for-woocommerce
Remove Fields from woocommerce Checkout page
Virtual product checkout field manager for WooCommerce
virtual-product-checkout-fields-manager
Virtual product checkout field manager for WooCommerce is an awesome plugin with nice admin control to hide checkout fields for virtual and downloadab …
Catalogue Custom Register Fields
catalogue-custom-register-fields
Catalogue Custom Register Fields in your wordpress is to add billing fields in registration form.
Hide Address Fields for WooCommerce Developer Profile
7 plugins · 10K total installs
How We Detect Hide Address Fields for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/hide-address-fields-for-woocommerce/assets/css/haf-style.css/wp-content/plugins/hide-address-fields-for-woocommerce/assets/js/haf-script.js/wp-content/plugins/hide-address-fields-for-woocommerce/assets/js/haf-script.js/wp-content/plugins/hide-address-fields-for-woocommerce/assets/css/haf-style.css?ver=/wp-content/plugins/hide-address-fields-for-woocommerce/assets/js/haf-script.js?ver=HTML / DOM Fingerprints
wc_haf_shipping_optionswc_haf_payment_optionsdata-shipping_methoddata-payment_methodwc_haf_shipping_methodswc_haf_payment_methods[haf_shipping_options][haf_payment_options]