Autofilll HKGov Address For WC Security & Risk Analysis

wordpress.org/plugins/wc-hkgov-address-autofill

Search and autofill the checkout form with Hong Kong Gov address or Google Place API.

0 active installs v1.0.5 PHP 5.4+ WP 5.0+ Updated Oct 28, 2022
autocompletegoogle-address-autocompletehkhong-konghong-kong-address-autocomplete
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Autofilll HKGov Address For WC Safe to Use in 2026?

Generally Safe

Score 85/100

Autofilll HKGov Address For WC has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The wc-hkgov-address-autofill plugin, version 1.0.5, exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code demonstrates good practices by not utilizing dangerous functions, performing file operations, or making external HTTP requests. The use of prepared statements for all SQL queries and the presence of at least one capability check are positive indicators. However, a notable concern is the relatively low percentage of properly escaped output (45%), which could expose the plugin to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient care in the unescaped outputs. The bundled Select2 library, while common, should be monitored for known vulnerabilities, although none are explicitly reported for this plugin.

The lack of any recorded vulnerabilities, including CVEs, is a significant strength and suggests a history of responsible development and patching. The absence of critical or high-severity taint flows further reinforces this. Despite the good overall hygiene, the unescaped output remains a potential weakness that could be exploited, especially if the plugin interacts with user-provided data. The security of bundled libraries should also be considered a potential, albeit currently unrealized, risk. In conclusion, while the plugin demonstrates many excellent security practices and has a clean vulnerability record, the unescaped output percentage warrants attention to prevent potential XSS issues.

Key Concerns

  • Low percentage of properly escaped output
  • Bundled library (Select2) could have vulnerabilities
Vulnerabilities
None known

Autofilll HKGov Address For WC Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Autofilll HKGov Address For WC Release Timeline

No version history available.
Code Analysis
Analyzed Mar 17, 2026

Autofilll HKGov Address For WC Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
6
5 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
1

Bundled Libraries

Select2

Output Escaping

45% escaped11 total outputs
Attack Surface

Autofilll HKGov Address For WC Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
actionadmin_menuhkgov-address-autofill.php:15
actionwp_enqueue_scriptshkgov-address-autofill.php:19
actionwoocommerce_before_checkout_billing_formhkgov-address-autofill.php:23
actionwoocommerce_before_checkout_shipping_formhkgov-address-autofill.php:27
actionadmin_initincludes\class-address-field-setting.php:12
actionhkaf_settings_tab_headingincludes\class-address-field-setting.php:17
actionhkaf_settings_tab_contentincludes\class-address-field-setting.php:22
Maintenance & Trust

Autofilll HKGov Address For WC Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedOct 28, 2022
PHP min version5.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Autofilll HKGov Address For WC Developer Profile

kyktommy

1 plugin · 0 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Autofilll HKGov Address For WC

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-hkgov-address-autofill/assets/css/select2.css/wp-content/plugins/wc-hkgov-address-autofill/assets/js/select2.min.js/wp-content/plugins/wc-hkgov-address-autofill/assets/js/autofill.js
Script Paths
https://maps.googleapis.com/maps/api/js?key=/assets/js/select2.min.js/assets/js/autofill.js
Version Parameters
wc-hkgov-address-autofill/assets/css/select2.css?ver=wc-hkgov-address-autofill/assets/js/select2.min.js?ver=wc-hkgov-address-autofill/assets/js/autofill.js?ver=

HTML / DOM Fingerprints

CSS Classes
billing-autofill-fieldshipping-autofill-field
Data Attributes
data-autofill_typedata-autofill_for_billingdata-autofill_for_shipping
JS Globals
hkaf
FAQ

Frequently Asked Questions about Autofilll HKGov Address For WC