
US Address Lookup by Zip Code Security & Risk Analysis
wordpress.org/plugins/us-address-lookup-by-zip-codeThis plugin allows you to auto-fill the address and related fields by putting zip code.
Is US Address Lookup by Zip Code Safe to Use in 2026?
Generally Safe
Score 85/100US Address Lookup by Zip Code has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "us-address-lookup-by-zip-code" v1.0.2 plugin presents a significant security risk due to its unprotected entry points and lack of robust security checks. While the static analysis did not identify any dangerous functions, critical taint flows, or bundled libraries, the presence of three AJAX handlers without any authentication or capability checks is a major concern. This means any unauthenticated user could potentially interact with these handlers, leading to unexpected behavior or unauthorized actions if the handlers perform sensitive operations or process user-supplied data insecurely.
The code also shows a complete absence of nonce checks, which are crucial for preventing Cross-Site Request Forgery (CSRF) attacks. Furthermore, all SQL queries are performed without prepared statements, exposing the plugin to SQL injection vulnerabilities. Although there is a good output escaping rate (80%), this does not mitigate the risks associated with unsanitized input being used in SQL queries or unprotected AJAX endpoints.
The plugin's vulnerability history is clean, with no recorded CVEs. This might suggest that the plugin hasn't been widely targeted or thoroughly scrutinized for vulnerabilities, or that past versions were secure. However, the current analysis reveals several concerning practices that could lead to exploitable vulnerabilities. The lack of authentication and capability checks on critical entry points, combined with raw SQL queries, are immediate and severe security weaknesses that require urgent attention.
Key Concerns
- AJAX handlers without auth checks
- Raw SQL queries without prepared statements
- Missing nonce checks on AJAX
- Capability checks missing
US Address Lookup by Zip Code Security Vulnerabilities
US Address Lookup by Zip Code Code Analysis
SQL Query Safety
Output Escaping
US Address Lookup by Zip Code Attack Surface
AJAX Handlers 3
WordPress Hooks 26
Maintenance & Trust
US Address Lookup by Zip Code Maintenance & Trust
Maintenance Signals
Community Trust
US Address Lookup by Zip Code Alternatives
WP Contact Slider – Contact Form Slider Widget
wp-contact-slider
Helps you to show slide out contact form to display CF7, Gravity forms, Ninja Forms, WP Forms, display random text/HTML and support some other forms.
Integration for Mailchimp and Contact Form 7, WPForms, Elementor, Ninja Forms
cf7-mailchimp
Send Contact Form 7, WPforms, Elementor, Ninja Forms, CRM Perks Forms and many other contact form submissions to Mailchimp.
Integration for HubSpot and Contact Form 7, WPForms, Elementor, Ninja Forms
cf7-hubspot
Send Contact Form 7, WPForms, Elementor, Ninja Forms, WPforms, Elementor, Ninja Forms, Contact Form Entries Plugin and many other contact form submiss …
WP Zoho for Contact Form 7, WPForms, Elementor, Formidable and Ninja Forms – CRM, Bigin
cf7-zoho
Send Contact Form 7, WPforms, Elementor, Formidable, Ninja Forms and many other contact form submissions to zoho CRM and Bigin.
Autopreenchimento de endereço em formulários
cf7-cep-autofill
Preenchimento automático de campos de endereço baseado no CEP informado.
US Address Lookup by Zip Code Developer Profile
12 plugins · 32K total installs
How We Detect US Address Lookup by Zip Code
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/us-address-lookup-by-zip-code/assets/css/style.css/wp-content/plugins/us-address-lookup-by-zip-code/assets/js/main.js/wp-content/plugins/us-address-lookup-by-zip-code/assets/js/jquery.zip.js/wp-content/plugins/us-address-lookup-by-zip-code/assets/js/main.js/wp-content/plugins/us-address-lookup-by-zip-code/assets/js/jquery.zip.js/wp-content/plugins/us-address-lookup-by-zip-code/assets/css/style.css?ver=/wp-content/plugins/us-address-lookup-by-zip-code/assets/js/main.js?ver=/wp-content/plugins/us-address-lookup-by-zip-code/assets/js/jquery.zip.js?ver=HTML / DOM Fingerprints
<!-- This file is used to define admin functions in order to carry out --><!-- the connections between any objects that are needed for the theme --><!-- and the WordPress core. More information, please visit. --><!-- https://developer.wordpress.org/plugins/ -->+8 moredata-usz-zipdata-usz-citydata-usz-statedata-usz-addressdata-usz-zip-valuedata-usz-city-value+6 moreusz_nonce_data/wp-json/usz/v1/get_address_by_zip