
Residential Address Detection Security & Risk Analysis
wordpress.org/plugins/residential-address-detectionReal-time identification of residential and commercial address types.
Is Residential Address Detection Safe to Use in 2026?
Generally Safe
Score 93/100Residential Address Detection has a strong security track record. Known vulnerabilities have been patched promptly.
The "residential-address-detection" plugin v2.5.11 exhibits a mixed security posture. On the positive side, the static analysis reveals strong adherence to several security best practices, including the absence of dangerous functions, 100% usage of prepared statements for SQL queries, and a robust implementation of nonce and capability checks for all identified AJAX entry points. Taint analysis also shows no critical or high-severity unsanitized flows, which is commendable.
However, a significant concern arises from the plugin's vulnerability history. With three known CVEs, including a past critical vulnerability, and a recent vulnerability discovered in July 2025, there's a clear pattern of past security weaknesses. While none are currently unpatched, the prevalence of 'Missing Authorization' as a common vulnerability type suggests a recurring area of weakness that requires ongoing vigilance.
The primary weakness identified in the code analysis is the moderate percentage of improperly escaped output (45%). While not as critical as unpatched vulnerabilities or unsanitized taint flows, this could still lead to Cross-Site Scripting (XSS) vulnerabilities in certain scenarios. In conclusion, while the current version of the plugin has addressed past critical vulnerabilities and implements good practices around SQL and AJAX handling, the historical trend and the output escaping issues warrant attention.
Key Concerns
- 45% of output not properly escaped
- Past critical CVE (unpatched history)
- Recent CVE (2025-07-16)
- Two medium CVEs in history
Residential Address Detection Security Vulnerabilities
CVEs by Year
Severity Breakdown
3 total CVEs
Residential Address Detection <= 2.5.9 - Missing Authorization
Residential Address Detection <= 2.5.4 - Missing Authorization
Residential Address Detection <= 2.5.4 - Unauthenticated Arbitrary Options Update
Residential Address Detection Code Analysis
Output Escaping
Data Flow Analysis
Residential Address Detection Attack Surface
AJAX Handlers 9
WordPress Hooks 13
Maintenance & Trust
Residential Address Detection Maintenance & Trust
Maintenance Signals
Community Trust
Residential Address Detection Alternatives
No alternatives data available yet.
Residential Address Detection Developer Profile
29 plugins · 1K total installs
How We Detect Residential Address Detection
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/residential-address-detection/includes/addresses/css/en-rad-style.css/wp-content/plugins/residential-address-detection/includes/addresses/js/en-rad-update-form.js/wp-content/plugins/residential-address-detection/includes/addresses/js/en-rad-address-submit-form.js/wp-content/plugins/residential-address-detection/includes/addresses/js/en-rad-update-form.js/wp-content/plugins/residential-address-detection/includes/addresses/js/en-rad-address-submit-form.jsen-rad-update-form.js?ver=1.1.1en-rad-address-submit-form.js?ver=1.1.1en-rad-style.css?ver=1.3.3HTML / DOM Fingerprints
rad_address_script