
Balcão Balcão Security & Risk Analysis
wordpress.org/plugins/balcao-balcaoPlugin de integração da plataforma Balcão Balcão para Wordpress.
Is Balcão Balcão Safe to Use in 2026?
Generally Safe
Score 85/100Balcão Balcão has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "balcao-balcao" plugin v1.0.5 exhibits a mixed security posture. On the positive side, it demonstrates good practices regarding SQL queries, exclusively using prepared statements, and ensures all output is properly escaped, which significantly mitigates common injection and cross-site scripting vulnerabilities. The absence of known vulnerabilities in its history is also a strong indicator of past security diligence.
However, the static analysis reveals significant concerns. The plugin exposes one REST API route without any permission callbacks, creating a direct, unprotected entry point into the application. This lack of authentication or authorization checks on this REST API endpoint is a critical security flaw. Furthermore, the absence of nonce checks on AJAX handlers, though there are no AJAX handlers reported, indicates a potential oversight in how future dynamic content might be handled, and more importantly, the current unprotected REST API route serves as a major concern.
While the plugin has no recorded vulnerability history, this does not guarantee future safety, especially given the identified unprotected REST API endpoint. The overall security is compromised by this single, but severe, unprotected entry point. Developers should prioritize adding proper authentication and authorization checks to all exposed endpoints, especially REST API routes. The strengths in SQL and output handling are commendable, but the critical weakness in exposed API access needs immediate attention.
Key Concerns
- REST API route without permission callbacks
- No nonce checks on AJAX handlers (potential future risk)
- No capability checks on entry points
Balcão Balcão Security Vulnerabilities
Balcão Balcão Code Analysis
Output Escaping
Balcão Balcão Attack Surface
REST API Routes 1
WordPress Hooks 5
Maintenance & Trust
Balcão Balcão Maintenance & Trust
Maintenance Signals
Community Trust
Balcão Balcão Alternatives
Calculadora de Frete e Campos Checkout para o Brasil
woo-better-shipping-calculator-for-brazil
Shipping calculator for Brazilian WooCommerce stores with automatic Postal Code address pre-filling and Brazilian Market on WooCommerce.
Envio Ecom
envioecom-shipping
Envio Ecom (EnvioEcom): calcula frete em tempo real no checkout com as melhores transportadoras do Brasil. EnvioEcom · envio ecom.
Shipping Simulator for WooCommerce
shipping-simulator-for-woocommerce
Allows customers to calculate the shipping rates on the product page in your WooCommerce store.
Pagar.me para WooCommerce
pagarme-payments-for-woocommerce
Aceite diversos métodos de pagamento de forma simples e segura utilizando o Pagar.me!
PagBank / PagSeguro Connect para WooCommerce
pagbank-connect
PagBank com PIX, Cartão de Crédito, Boleto, Recorrência + Envio Fácil e com Menos Taxas no PagSeguro. Autenticação 3D: menos chargeback + aprovações.
Balcão Balcão Developer Profile
1 plugin · 0 total installs
How We Detect Balcão Balcão
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/balcao-balcao/includes/balcaobalcao-shipping.css/wp-content/plugins/balcao-balcao/includes/balcaobalcao-shipping.js/wp-content/plugins/balcao-balcao/includes/balcaobalcao-shipping.jsbalcao-balcao/includes/balcaobalcao-shipping.css?ver=balcao-balcao/includes/balcaobalcao-shipping.js?ver=HTML / DOM Fingerprints
balcaobalcao-shipping-optionsbalcaobalcao-settings-fieldbalcaobalcao-title<!-- Balcão Balcão Shipping Method --><!-- Balcão Balcão Settings --><!-- Balcão Balcão JavaScript -->data-balcaobalcao-debugdata-balcaobalcao-tokendata-balcaobalcao-endpointbalcaobalcao_params/wp-json/balcaobalcao/v1/legacy-callback