Dino Divulgador de Notícias Security & Risk Analysis

wordpress.org/plugins/dino-divulgador-de-noticias

External services

10 active installs v3.4 PHP 8.0+ WP 4.6+ Updated Oct 8, 2025
conhecimentocorporativoinformacoesnegociosnoticias
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Dino Divulgador de Notícias Safe to Use in 2026?

Generally Safe

Score 100/100

Dino Divulgador de Notícias has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The 'dino-divulgador-de-noticias' v3.4 plugin exhibits a concerning security posture, primarily due to a significant attack surface that is entirely unprotected. With 10 REST API routes lacking any permission callbacks, all of these entry points are exposed to unauthorized access. While the plugin demonstrates good practices in other areas, such as perfect output escaping and the absence of dangerous functions or file operations, this fundamental flaw in access control for its REST API is a major vulnerability. The plugin's vulnerability history is clean, with no recorded CVEs, suggesting past development might have been more secure or less scrutinized. However, the current static analysis highlights a critical weakness that, if exploited, could lead to unauthorized data manipulation or disclosure. The presence of nonce checks and some use of prepared statements are positive signs, but they do not mitigate the immediate risk posed by the unprotected REST API endpoints. The plugin's strengths in output sanitization and lack of known vulnerabilities are overshadowed by the lack of authentication on its primary entry points.

Key Concerns

  • REST API routes without permission callbacks
  • Large attack surface without auth
  • Capability checks: 0
Vulnerabilities
None known

Dino Divulgador de Notícias Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Dino Divulgador de Notícias Code Analysis

Dangerous Functions
0
Raw SQL Queries
30
36 prepared
Unescaped Output
0
118 escaped
Nonce Checks
2
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

55% prepared66 total queries

Output Escaping

100% escaped118 total outputs
Attack Surface
10 unprotected

Dino Divulgador de Notícias Attack Surface

Entry Points10
Unprotected10

REST API Routes 10

POST/wp-json/dino-divulgador-de-noticias/v1/authdino-divulgador-de-noticias\includes\class-dino-auth.php:21
POST/wp-json/dino-divulgador-de-noticias/v1/delete-newsdino-divulgador-de-noticias\includes\class-dino-delete.php:18
POST/wp-json/dino-divulgador-de-noticias/v1/logsdino-divulgador-de-noticias\includes\class-dino-logs.php:18
POST/wp-json/dino-divulgador-de-noticias/v1/publishdino-divulgador-de-noticias\includes\class-dino-publish.php:18
POST/wp-json/dino-divulgador-de-noticias/v1/versiondino-divulgador-de-noticias\includes\class-dino-version.php:18
POST/wp-json/dino-divulgador-de-noticias/v1/authincludes\class-dino-auth.php:21
POST/wp-json/dino-divulgador-de-noticias/v1/delete-newsincludes\class-dino-delete.php:18
POST/wp-json/dino-divulgador-de-noticias/v1/logsincludes\class-dino-logs.php:18
POST/wp-json/dino-divulgador-de-noticias/v1/publishincludes\class-dino-publish.php:18
POST/wp-json/dino-divulgador-de-noticias/v1/versionincludes\class-dino-version.php:18
WordPress Hooks 20
actionrest_api_initdino-divulgador-de-noticias\includes\class-dino-auth.php:17
actionrest_api_initdino-divulgador-de-noticias\includes\class-dino-delete.php:14
actionrest_api_initdino-divulgador-de-noticias\includes\class-dino-logs.php:14
actionrest_api_initdino-divulgador-de-noticias\includes\class-dino-publish.php:14
actionrest_api_initdino-divulgador-de-noticias\includes\class-dino-version.php:14
actionadmin_menudino-divulgador-de-noticias\includes\functions.php:6
actioninitdino-divulgador-de-noticias\includes\functions.php:48
actionadmin_post_dino_user_ajaxdino-divulgador-de-noticias\includes\functions.php:326
actionadmin_post_dino_remover_categoria_ajaxdino-divulgador-de-noticias\includes\functions.php:336
actionadmin_post_dino_categoria_ajaxdino-divulgador-de-noticias\includes\functions.php:353
actionrest_api_initincludes\class-dino-auth.php:17
actionrest_api_initincludes\class-dino-delete.php:14
actionrest_api_initincludes\class-dino-logs.php:14
actionrest_api_initincludes\class-dino-publish.php:14
actionrest_api_initincludes\class-dino-version.php:14
actionadmin_menuincludes\functions.php:6
actioninitincludes\functions.php:48
actionadmin_post_dino_user_ajaxincludes\functions.php:326
actionadmin_post_dino_remover_categoria_ajaxincludes\functions.php:336
actionadmin_post_dino_categoria_ajaxincludes\functions.php:353
Maintenance & Trust

Dino Divulgador de Notícias Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.5
Last updatedOct 8, 2025
PHP min version8.0
Downloads259

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Dino Divulgador de Notícias Developer Profile

dinoknewin

1 plugin · 10 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Dino Divulgador de Notícias

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

REST Endpoints
dino-divulgador-de-noticias/v1dino-divulgador-de-noticias/v1/authdino-divulgador-de-noticias/v1/delete-news
FAQ

Frequently Asked Questions about Dino Divulgador de Notícias