
Autofilll HKGov Address For WC Security & Risk Analysis
wordpress.org/plugins/wc-hkgov-address-autofillSearch and autofill the checkout form with Hong Kong Gov address or Google Place API.
Is Autofilll HKGov Address For WC Safe to Use in 2026?
Generally Safe
Score 85/100Autofilll HKGov Address For WC has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The wc-hkgov-address-autofill plugin, version 1.0.5, exhibits a generally strong security posture based on the provided static analysis and vulnerability history. The complete absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the potential attack surface. Furthermore, the code demonstrates good practices by not utilizing dangerous functions, performing file operations, or making external HTTP requests. The use of prepared statements for all SQL queries and the presence of at least one capability check are positive indicators. However, a notable concern is the relatively low percentage of properly escaped output (45%), which could expose the plugin to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled with sufficient care in the unescaped outputs. The bundled Select2 library, while common, should be monitored for known vulnerabilities, although none are explicitly reported for this plugin.
The lack of any recorded vulnerabilities, including CVEs, is a significant strength and suggests a history of responsible development and patching. The absence of critical or high-severity taint flows further reinforces this. Despite the good overall hygiene, the unescaped output remains a potential weakness that could be exploited, especially if the plugin interacts with user-provided data. The security of bundled libraries should also be considered a potential, albeit currently unrealized, risk. In conclusion, while the plugin demonstrates many excellent security practices and has a clean vulnerability record, the unescaped output percentage warrants attention to prevent potential XSS issues.
Key Concerns
- Low percentage of properly escaped output
- Bundled library (Select2) could have vulnerabilities
Autofilll HKGov Address For WC Security Vulnerabilities
Autofilll HKGov Address For WC Release Timeline
Autofilll HKGov Address For WC Code Analysis
Bundled Libraries
Output Escaping
Autofilll HKGov Address For WC Attack Surface
WordPress Hooks 7
Maintenance & Trust
Autofilll HKGov Address For WC Maintenance & Trust
Maintenance Signals
Community Trust
Autofilll HKGov Address For WC Alternatives
Autocomplete Google Address
autocomplete-google-address
The #1 Google Address Autocomplete for WordPress. Visual point-and-click setup -- no coding needed. Works with WooCommerce, CF7, WPForms, Gravity Form …
Autocomplete Location Field for Contact Form 7
autocomplete-location-field-contact-form-7
Add Google Places Autocomplete address field to Contact Form 7. Enable automatic address suggestions using Google Maps API for faster and more accurat …
Checkout Address AutoFill For WooCommerce
checkout-address-autofill-for-woocommerce
Checkout Address AutoFill For WooCommerce is a WooCommerce add-on which allows your user to autofill both Billing and Shipping address fields in the c …
Simple Address Autocomplete
simple-address-autocomplete
A simple way to add Google address autocomplete functionality to any form in WordPress. Limit the search to one country or worldwide.
Autocomplete Google places
autocomplete-google-places
This plugin will help you to use Place Autocomplete API key.
Autofilll HKGov Address For WC Developer Profile
1 plugin · 0 total installs
How We Detect Autofilll HKGov Address For WC
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/wc-hkgov-address-autofill/assets/css/select2.css/wp-content/plugins/wc-hkgov-address-autofill/assets/js/select2.min.js/wp-content/plugins/wc-hkgov-address-autofill/assets/js/autofill.jshttps://maps.googleapis.com/maps/api/js?key=/assets/js/select2.min.js/assets/js/autofill.jswc-hkgov-address-autofill/assets/css/select2.css?ver=wc-hkgov-address-autofill/assets/js/select2.min.js?ver=wc-hkgov-address-autofill/assets/js/autofill.js?ver=HTML / DOM Fingerprints
billing-autofill-fieldshipping-autofill-fielddata-autofill_typedata-autofill_for_billingdata-autofill_for_shippinghkaf