Darven Múltiplos Preços Informativos Security & Risk Analysis

wordpress.org/plugins/darven-multiplos-precos-informativos

Requires WooCommerce Mostra múltiplos preços em um produto. Preço á vista e com parcelamento (preço parcelado).

200 active installs v3.2.0 PHP 7.4+ WP 4.7+ Updated Jul 8, 2023
installmentsparcelamentoparcelasprecosprice
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Darven Múltiplos Preços Informativos Safe to Use in 2026?

Generally Safe

Score 85/100

Darven Múltiplos Preços Informativos has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "darven-multiplos-precos-informativos" plugin version 3.2.0 exhibits a generally strong security posture. The static analysis reveals no identified attack surface points, no dangerous functions used, and all SQL queries are properly prepared. Furthermore, the taint analysis found no unsanitized flows. The vulnerability history is also clean, with no recorded CVEs, indicating a consistent track record of security.

However, a few areas warrant attention. The plugin has zero nonces checks and zero capability checks across its codebase, which is a significant concern. While the current analysis might not have revealed direct vulnerabilities stemming from this, it leaves the plugin susceptible to various attacks if new entry points are introduced or if existing functionality is leveraged in unexpected ways. The 84% output escaping, while high, implies that 16% of outputs are not properly escaped, potentially leading to cross-site scripting (XSS) vulnerabilities.

In conclusion, the plugin demonstrates good practices in areas like SQL handling and avoiding dangerous functions. Its lack of past vulnerabilities is a positive sign. Nevertheless, the absence of nonces and capability checks, along with a small percentage of unescaped output, represent notable weaknesses that could be exploited. Vigilance is recommended, and future updates should prioritize addressing these specific oversight.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
  • 16% of output not properly escaped
Vulnerabilities
None known

Darven Múltiplos Preços Informativos Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Darven Múltiplos Preços Informativos Release Timeline

v3.1.3
v3.1.2
v3.1.1
v3.0.1
v3.
v3.0.0
v2.0.1
v2.0.0
v1.1.2
v1.1.0
v1.0.1
v1.0
Code Analysis
Analyzed Mar 16, 2026

Darven Múltiplos Preços Informativos Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
18
92 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

84% escaped110 total outputs
Attack Surface

Darven Múltiplos Preços Informativos Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
actionadmin_menuincludes\admin\settings\class-darven-epi-general-settings.php:16
actionadmin_initincludes\admin\settings\class-darven-epi-general-settings.php:17
actionadmin_menuincludes\admin\settings\class-epi-general-settings.php:9
actionadmin_initincludes\admin\settings\class-epi-general-settings.php:10
actionplugins_loadedincludes\class-darven-epi.php:96
actionadmin_enqueue_scriptsincludes\class-darven-epi.php:104
actionadmin_enqueue_scriptsincludes\class-darven-epi.php:105
actionwp_enqueue_scriptsincludes\class-darven-epi.php:114
actionwp_enqueue_scriptsincludes\class-darven-epi.php:115
filterwoocommerce_get_price_htmlincludes\class-darven-epi.php:120
actionwoocommerce_product_options_general_product_dataincludes\functions\class-darven-epi-product-options.php:11
actionwoocommerce_process_product_metaincludes\functions\class-darven-epi-product-options.php:16
Maintenance & Trust

Darven Múltiplos Preços Informativos Maintenance & Trust

Maintenance Signals

WordPress version tested6.2.9
Last updatedJul 8, 2023
PHP min version7.4
Downloads8K

Community Trust

Rating90/100
Number of ratings4
Active installs200
Developer Profile

Darven Múltiplos Preços Informativos Developer Profile

Letícia Moreira

2 plugins · 200 total installs

86
trust score
Avg Security Score
89/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Darven Múltiplos Preços Informativos

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/darven-extra-price-info/admin/css/admin_styles.css/wp-content/plugins/darven-extra-price-info/admin/js/colorsandstyles.js/wp-content/plugins/darven-extra-price-info/admin/js/general.js/wp-content/plugins/darven-extra-price-info/public/css/darven-epi-public.css/wp-content/plugins/darven-extra-price-info/public/js/darven-epi-public.js
Script Paths
/wp-content/plugins/darven-extra-price-info/admin/js/colorsandstyles.js/wp-content/plugins/darven-extra-price-info/admin/js/general.js/wp-content/plugins/darven-extra-price-info/public/js/darven-epi-public.js
Version Parameters
darven-extra-price-info/admin/css/admin_styles.css?ver=darven-extra-price-info/admin/js/colorsandstyles.js?ver=darven-extra-price-info/admin/js/general.js?ver=darven-epi-public.css?ver=darven-epi-public.js?ver=

HTML / DOM Fingerprints

CSS Classes
darven_epi_multi_pricedarven_epi_wrapper
HTML Comments
<!-- Darven Multiple Price Info --><!-- This plugin is used to show multiple prices for a product. Incash and installments price. -->
Data Attributes
data-darven_epi_product_id
JS Globals
darven_epi_params
Shortcode Output
[darven_epi_multi_price]
FAQ

Frequently Asked Questions about Darven Múltiplos Preços Informativos