
Cotação Moedas Security & Risk Analysis
wordpress.org/plugins/cotacao-moedas-hojeCotação do Dólar, Euro e Iene em relação ao Real (R$). Todos os dados são buscados do Banco Central do Brasil diariamente pelo Web Service.
Is Cotação Moedas Safe to Use in 2026?
Generally Safe
Score 85/100Cotação Moedas has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'cotacao-moedas-hoje' plugin version 1.0.2 exhibits a generally good security posture with no known vulnerabilities and a minimal attack surface. The static analysis reveals a single shortcode as the only entry point, and importantly, no AJAX handlers or REST API routes were found, which are common vectors for attacks. The complete absence of raw SQL queries and the use of prepared statements for all database interactions are significant strengths, indicating a commitment to secure database practices. File operations and external HTTP requests are also absent, further reducing the plugin's exposure to potential exploits. However, a notable concern is the low percentage of properly escaped output (24%). This indicates that a significant portion of dynamic content displayed to users may be vulnerable to cross-site scripting (XSS) attacks if the data originates from untrusted sources or user input. Furthermore, the lack of nonce checks and capability checks, while not directly tied to the identified entry points (which lack direct user interaction in the provided data), suggests a potential for privilege escalation or unauthorized actions if the plugin were to evolve or integrate with other components in the future. The absence of any recorded vulnerabilities, coupled with the current secure coding practices in place (prepared statements), is a positive indicator. Nevertheless, the insufficient output escaping remains a critical oversight that needs immediate attention to prevent potential XSS vulnerabilities.
Key Concerns
- Low percentage of properly escaped output
- No nonce checks
- No capability checks
Cotação Moedas Security Vulnerabilities
Cotação Moedas Code Analysis
Output Escaping
Cotação Moedas Attack Surface
Shortcodes 1
WordPress Hooks 11
Maintenance & Trust
Cotação Moedas Maintenance & Trust
Maintenance Signals
Community Trust
Cotação Moedas Alternatives
Cotação Dólar
cotacao-dolar-hoje
Cotação do Dólar em relação ao Real (moeda do Brasil). Tenha a cotação do dólar em seu site - atualizado diariamente direto do site do Banco Central d …
Cotação Euro
cotacao-euro-hoje
Cotação do Euro em relação ao Real (moeda do Brasil). Tenha a cotação do euro em seu site - atualizado diariamente direto do site do Banco Central do …
Melhor Envio
melhor-envio-cotacao
Requires Wordpress 4.0+ Requires WooCommerce 4.0+ License: GPLv3 License URI: https://www.gnu.org/licenses/gpl-3.0.html Plugin para cotação e compra d …
Cotação Moedas Developer Profile
1 plugin · 100 total installs
How We Detect Cotação Moedas
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/cotacao-moedas-hoje/admin/css/cmh-bcb-admin.css/wp-content/plugins/cotacao-moedas-hoje/admin/js/cmh-bcb-admin.js/wp-content/plugins/cotacao-moedas-hoje/public/css/cotacao-moedas-hoje-public.css/wp-content/plugins/cotacao-moedas-hoje/public/js/cotacao-moedas-hoje-public.jscotacao-moedas-hoje/admin/css/cmh-bcb-admin.css?ver=cotacao-moedas-hoje/admin/js/cmh-bcb-admin.js?ver=cotacao-moedas-hoje/public/css/cotacao-moedas-hoje-public.css?ver=cotacao-moedas-hoje/public/js/cotacao-moedas-hoje-public.js?ver=HTML / DOM Fingerprints
cmh-bcb-settings-sectioncmh-bcb-main-container<!-- This file is used to define the public-facing functionality of the plugin. --><!-- Start of cotacao-moedas-hoje shortcode --><!-- End of cotacao-moedas-hoje shortcode --><!-- Cotação Moedas Hoje Widget -->data-plugin-slug="cotacao-moedas-hoje"data-settings-page="cmh-bcb-settings"window.cmhBcbSettingsvar cmhBcbData<div class="cotacao-moedas-hoje-wrapper"><div id="cmh-bcb-currency-converter"></div><table class="cmh-bcb-rates-table"><thead>