
WC – APG NIF/CIF/NIE Field Security & Risk Analysis
wordpress.org/plugins/wc-apg-nifcifnie-fieldAdd to WooCommerce a NIF/CIF/NIE field.
Is WC – APG NIF/CIF/NIE Field Safe to Use in 2026?
Generally Safe
Score 100/100WC – APG NIF/CIF/NIE Field has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The plugin 'wc-apg-nifcifnie-field' v4.9.0 presents a significant security risk due to its unprotected AJAX endpoints. With 6 out of 6 AJAX handlers lacking authentication checks, any authenticated user on a WordPress site could potentially trigger these functions, leading to unauthorized actions. While the code analysis shows good practices in output escaping and no critical taint flows or dangerous functions, the absence of capability checks on these AJAX endpoints is a major concern. The plugin's clean vulnerability history is a positive sign, suggesting it has not had publicly disclosed vulnerabilities in the past. However, this does not mitigate the immediate risks identified in the current static analysis. The lack of proper authorization for a substantial portion of its attack surface is a weakness that outweighs its strengths in other areas.
Key Concerns
- Unprotected AJAX handlers
- Raw SQL queries without prepared statements
- Limited capability checks on entry points
WC – APG NIF/CIF/NIE Field Security Vulnerabilities
WC – APG NIF/CIF/NIE Field Code Analysis
SQL Query Safety
Output Escaping
WC – APG NIF/CIF/NIE Field Attack Surface
AJAX Handlers 6
WordPress Hooks 51
Maintenance & Trust
WC – APG NIF/CIF/NIE Field Maintenance & Trust
Maintenance Signals
Community Trust
WC – APG NIF/CIF/NIE Field Alternatives
Validar identidad CF7
validar-identidad-cf7
Valida campos de DNI, NIF, NIE y CIF utilizando el plugin Contact Form 7
WP-Optimize – Cache, Compress images, Minify & Clean database to boost page speed & performance
wp-optimize
Get caching and more with this powerful cache plugin. Cache, optimize images, clean your database and minify for maximum performance.
SpeedyCache – Cache, Optimization, Performance
speedycache
SpeedyCache is a WordPress cache plugin that helps you improve performance of your WordPress site by caching, minifying, and compressing your website.
Asset CleanUp: Page Speed Booster
wp-asset-clean-up
Make your website load FASTER by stopping specific styles (.CSS) & scripts (.JS) from loading. It works best with a page caching plugin / service.
Hummingbird Performance – Cache & Page Speed Optimization for Core Web Vitals | Critical CSS | Minify CSS | Defer CSS Javascript | CDN
hummingbird-performance
Optimize PageSpeed Performance & Core Web Vitals, Advanced Cache, Minify CSS & JavaScript, Inline Critical CSS, Defer CSS & JS, Smush & Lazy Load, CDN
WC – APG NIF/CIF/NIE Field Developer Profile
9 plugins · 19K total installs
How We Detect WC – APG NIF/CIF/NIE Field
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-apg-nifcifnie-field/assets/js/frontend/addresses.min.js/wp-content/plugins/wc-apg-nifcifnie-field/assets/js/admin/settings.min.js/wp-content/plugins/wc-apg-nifcifnie-field/assets/css/admin/settings.min.css/wp-content/plugins/wc-apg-nifcifnie-field/assets/js/frontend/addresses.min.js/wp-content/plugins/wc-apg-nifcifnie-field/assets/js/admin/settings.min.jswc-apg-nifcifnie-field/assets/js/frontend/addresses.min.js?ver=wc-apg-nifcifnie-field/assets/js/admin/settings.min.js?ver=wc-apg-nifcifnie-field/assets/css/admin/settings.min.css?ver=HTML / DOM Fingerprints
apg-nif-field-wrapperapg-nif-fieldapg-nif-labelapg-nif-inputapg-nif-error-messageapg-nif-validation-icons<!-- Campo NIF/CIF/NIE en Checkout --><!-- Campo NIF/CIF/NIE en Mi Cuenta --><!-- Campo NIF/CIF/NIE en Direcciones --><!-- Validation Icons -->data-apg-nif-settingsdata-apg-nif-validation-enableddata-apg-nif-vies-enableddata-apg-nif-eori-enableddata-apg-nif-error-messagedata-apg-nif-vies-error-message+4 moreAPG_NIF_FRONTEND_OBJECTapg_nif_frontend_params