
zipaddr-jp Security & Risk Analysis
wordpress.org/plugins/zipaddr-jpzipaddr-jp is a collaborative tool that automatically inputs addresses from postal codes.
Is zipaddr-jp Safe to Use in 2026?
Generally Safe
Score 100/100zipaddr-jp has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The zipaddr-jp plugin version 1.42 exhibits a generally strong security posture based on the provided static analysis. The absence of AJAX handlers, REST API routes, shortcodes, and cron events significantly limits the plugin's attack surface. Furthermore, the adherence to prepared statements for all SQL queries and proper output escaping demonstrates good development practices. The single nonce check, while present, is a positive indicator, although the complete lack of capability checks on any entry points is a notable weakness that could allow unauthorized actions if an entry point were discovered or created.
The static analysis did identify two dangerous 'unserialize' function calls, and importantly, these 'unserialize' calls were part of flows with unsanitized paths. While the taint analysis did not flag these as critical or high severity, the use of 'unserialize' on potentially untrusted data is inherently risky and can lead to remote code execution vulnerabilities if not handled with extreme care and strict input validation. The plugin's history of zero known vulnerabilities is a positive sign, suggesting a diligent approach to security in the past, but it does not negate the inherent risks identified in the code.
In conclusion, while the plugin benefits from a small attack surface and sound practices in SQL and output handling, the presence of unsanitized 'unserialize' calls represents a significant potential risk. The lack of capability checks on any entry points further exacerbates this, creating a scenario where an attacker could potentially exploit the 'unserialize' functionality if they could trigger it. The plugin has a good foundation but requires careful review and mitigation for the identified 'unserialize' flows.
Key Concerns
- Unsanitized path in unserialize flow
- Unsanitized path in unserialize flow
- Dangerous function: unserialize
- No capability checks on entry points
zipaddr-jp Security Vulnerabilities
zipaddr-jp Release Timeline
zipaddr-jp Code Analysis
Dangerous Functions Found
Output Escaping
Data Flow Analysis
zipaddr-jp Attack Surface
WordPress Hooks 5
Maintenance & Trust
zipaddr-jp Maintenance & Trust
Maintenance Signals
Community Trust
zipaddr-jp Alternatives
autoin-jp
autoin-jp
The ultimate automatic input tool, autoin-jp, works only in the Japanese version. The operating environment is as follows. Wordpress 5.
yuban-jp
yuban-jp
This is a tool that automatically enters addresses from postal codes.
US Address Lookup by Zip Code
us-address-lookup-by-zip-code
This plugin allows you to auto-fill the address and related fields by putting zip code.
myform-jp
myform-jp
This software is inquiry form for the individual. It works only in Japanese.
Astra Widgets
astra-widgets
Quickest solution to add widgets like Address, Social Profiles and List icons on a website built with Astra.
zipaddr-jp Developer Profile
4 plugins · 50K total installs
How We Detect zipaddr-jp
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/zipaddr-jp/js/zipaddr.js/wp-content/plugins/zipaddr-jp/css/zipaddr.csshttps://zipaddr.com/js/zipaddr7.js?v=1.42https://zipaddr.github.io/zipaddr3.js?v=1.42https://zipaddr.github.io/zipaddr30.js?v=1.42https://zipaddr.github.io/zipaddrx.js?v=1.42https://zipaddr.github.io/zipaddra.js?v=1.42zipaddr-jp/style.css?ver=zipaddr.js?v=1.42HTML / DOM Fingerprints
zipaddr-formzipaddr-inputzipaddr-buttonzipaddr-label<!-- ZIPADDRJP Start --><!-- ZIPADDRJP End --><!-- Contact Form 7 --><!-- MW WP Form -->+15 moredata-zipaddr-targetdata-zipaddr-buttondata-zipaddr-zipdata-zipaddr-prefdata-zipaddr-citydata-zipaddr-town+1 morezipaddr_ownbzipaddr_dataZipdelivery_countrydelivery_pref[zipcode]