Departamentos y Ciudades de Colombia para Woocommerce Security & Risk Analysis

wordpress.org/plugins/departamentos-y-ciudades-de-colombia-para-woocommerce

WordPress plugin that shows dropdowns for State and City Select for WooCommerce

7K active installs v2.0.22 PHP 8.0+ WP 6.0+ Updated Mar 24, 2025
ciudadescolombiadepartamentoswoocommerce-ciudades-de-colombiawoocommerce-departamentos-de-colombia
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Departamentos y Ciudades de Colombia para Woocommerce Safe to Use in 2026?

Generally Safe

Score 92/100

Departamentos y Ciudades de Colombia para Woocommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The plugin "departamentos-y-ciudades-de-colombia-para-woocommerce" v2.0.22 exhibits a generally good security posture based on the provided static analysis. The absence of dangerous functions, the complete use of prepared statements for SQL queries, and the lack of external HTTP requests are positive indicators. Furthermore, the vulnerability history shows no known CVEs, suggesting a well-maintained codebase or a lack of past exploitable issues.

However, there are areas for improvement. The static analysis reveals that 44% of output is not properly escaped. This could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is displayed without sufficient sanitization. Additionally, the complete lack of nonce checks and capability checks across all entry points, including the single shortcode, is a significant concern. This means that any user, regardless of their role or authentication status, could potentially trigger actions associated with this shortcode, opening the door for unauthorized operations or information disclosure.

In conclusion, while the plugin has strong foundations in its database interactions and avoids common pitfalls like dangerous functions, the lack of robust input validation and authorization checks on its shortcode represents a notable security weakness. Addressing the unescaped output and implementing proper nonce and capability checks on the shortcode should be prioritized to strengthen its overall security.

Key Concerns

  • Significant portion of output not properly escaped
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Departamentos y Ciudades de Colombia para Woocommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Departamentos y Ciudades de Colombia para Woocommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
15
19 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

56% escaped34 total outputs
Attack Surface

Departamentos y Ciudades de Colombia para Woocommerce Attack Surface

Entry Points1
Unprotected0

Shortcodes 1

[fee] includes\filter-by-cities.php:269
WordPress Hooks 11
actionplugins_loadeddepartamentos-y-ciudades-de-colombia-para-woocommerce.php:21
actionbefore_woocommerce_initdepartamentos-y-ciudades-de-colombia-para-woocommerce.php:22
filterwoocommerce_shipping_methodsdepartamentos-y-ciudades-de-colombia-para-woocommerce.php:52
filterwoocommerce_default_address_fieldsdepartamentos-y-ciudades-de-colombia-para-woocommerce.php:57
actionwoocommerce_shipping_initdepartamentos-y-ciudades-de-colombia-para-woocommerce.php:66
filterwoocommerce_package_ratesincludes\filter-by-cities.php:179
filterwoocommerce_statesincludes\states-places.php:38
filterwoocommerce_billing_fieldsincludes\states-places.php:46
filterwoocommerce_shipping_fieldsincludes\states-places.php:47
filterwoocommerce_form_field_cityincludes\states-places.php:48
actionwp_enqueue_scriptsincludes\states-places.php:50
Maintenance & Trust

Departamentos y Ciudades de Colombia para Woocommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedMar 24, 2025
PHP min version8.0
Downloads166K

Community Trust

Rating88/100
Number of ratings19
Active installs7K
Developer Profile

Departamentos y Ciudades de Colombia para Woocommerce Developer Profile

Saul Morales Pacheco

11 plugins · 8K total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Departamentos y Ciudades de Colombia para Woocommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/departamentos-y-ciudades-de-colombia-para-woocommerce/assets/css/states-places-colombia.css/wp-content/plugins/departamentos-y-ciudades-de-colombia-para-woocommerce/assets/js/states-places-colombia.js
Version Parameters
departamentos-y-ciudades-de-colombia-para-woocommerce/assets/css/states-places-colombia.css?ver=departamentos-y-ciudades-de-colombia-para-woocommerce/assets/js/states-places-colombia.js?ver=

HTML / DOM Fingerprints

CSS Classes
city_select
Data Attributes
data-priority
FAQ

Frequently Asked Questions about Departamentos y Ciudades de Colombia para Woocommerce