
Manda Bem Security & Risk Analysis
wordpress.org/plugins/mandabemIntegration between the Manda Bem Platform and WooCommerce
Is Manda Bem Safe to Use in 2026?
Generally Safe
Score 85/100Manda Bem has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mandabem" v2.0 plugin exhibits a concerning security posture due to its unprotected entry points. While it demonstrates good practices in avoiding dangerous functions, using prepared statements for SQL queries, and properly escaping most output, the presence of two REST API routes without permission callbacks represents a significant security weakness. This means any unauthenticated user could potentially interact with these API endpoints, leading to unintended consequences or data exposure if these endpoints handle sensitive operations.
The static analysis also reveals a lack of nonce checks and a limited number of capability checks, further contributing to the concern over unprotected entry points. The absence of taint analysis results is neutral, as it might indicate a lack of complex data flows or that the analysis was not performed exhaustively. The plugin's history of no known vulnerabilities is a positive sign, suggesting good past development, but it does not negate the immediate risks identified in the current version's code.
In conclusion, "mandabem" v2.0 has some strengths in its coding practices regarding data handling and SQL. However, the critical flaw of unprotected REST API routes overshadows these strengths. The attack surface is small but entirely exposed, creating a high-risk scenario for these specific entry points. Users should exercise extreme caution or avoid using this plugin until the identified security flaws are addressed.
Key Concerns
- REST API routes without permission callbacks
- AJAX handlers without auth checks
- No nonce checks
- Low number of capability checks
- Less than 100% output escaping
Manda Bem Security Vulnerabilities
Manda Bem Code Analysis
Output Escaping
Manda Bem Attack Surface
REST API Routes 2
WordPress Hooks 21
Maintenance & Trust
Manda Bem Maintenance & Trust
Maintenance Signals
Community Trust
Manda Bem Alternatives
Claudio Sanches – Correios for WooCommerce
woocommerce-correios
Integration between the Correios and WooCommerce
Autocomplete Address for WooCommerce
autocomplete-address-for-woocommerce
Preencha automaticamente o endereço a partir do CEP no WooCommerce
Frenet Shipping Gateway for WooCommerce – Correios, Etiquetas e Rastreio
woo-shipping-gateway
Frete inteligente, simples e acessível para negócios que querem crescer
Correios Automático – Rastreio, Frete, Etiqueta, Declaração e Devolução
infixs-correios-automatico
Integração com correios automatizada (Tudo em um), com ou sem contrato, código de rastreio automático, geração de etiquetas, devolução e muito mais.
FPG – Endereço automático por Cep no Checkout
fpg-endereco-automatico-por-cep-no-checkout
Preenche o endereço, no checkout, automáticamente através do cep.
Manda Bem Developer Profile
1 plugin · 200 total installs
How We Detect Manda Bem
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mandabem/assets/js/wc-mandabem-cart.js/wp-content/plugins/mandabem/assets/js/wc-mandabem-checkout.js/wp-content/plugins/mandabem/assets/css/wc-mandabem-checkout.css/wp-content/plugins/mandabem/assets/js/wc-mandabem-cart.js/wp-content/plugins/mandabem/assets/js/wc-mandabem-checkout.jsmandabem/assets/js/wc-mandabem-cart.js?ver=mandabem/assets/js/wc-mandabem-checkout.js?ver=mandabem/assets/css/wc-mandabem-checkout.css?ver=HTML / DOM Fingerprints
mandabem-shipping-delivery-infodata-mandabem-shipping-methoddata-mandabem-tracking-codedata-mandabem-delivery-estimatewc_mandabem_cart_paramswc_mandabem_checkout_params/wp-json/mandabem/update_rastreio/wp-json/mandabem/update_entrega