
Manda Bem Security & Risk Analysis
wordpress.org/plugins/mandabemIntegration between the Manda Bem Platform and WooCommerce
Is Manda Bem Safe to Use in 2026?
Generally Safe
Score 100/100Manda Bem has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "mandabem" v2.0 plugin exhibits a concerning security posture due to its unprotected entry points. While it demonstrates good practices in avoiding dangerous functions, using prepared statements for SQL queries, and properly escaping most output, the presence of two REST API routes without permission callbacks represents a significant security weakness. This means any unauthenticated user could potentially interact with these API endpoints, leading to unintended consequences or data exposure if these endpoints handle sensitive operations.
The static analysis also reveals a lack of nonce checks and a limited number of capability checks, further contributing to the concern over unprotected entry points. The absence of taint analysis results is neutral, as it might indicate a lack of complex data flows or that the analysis was not performed exhaustively. The plugin's history of no known vulnerabilities is a positive sign, suggesting good past development, but it does not negate the immediate risks identified in the current version's code.
In conclusion, "mandabem" v2.0 has some strengths in its coding practices regarding data handling and SQL. However, the critical flaw of unprotected REST API routes overshadows these strengths. The attack surface is small but entirely exposed, creating a high-risk scenario for these specific entry points. Users should exercise extreme caution or avoid using this plugin until the identified security flaws are addressed.
Key Concerns
- REST API routes without permission callbacks
- AJAX handlers without auth checks
- No nonce checks
- Low number of capability checks
- Less than 100% output escaping
Manda Bem Security Vulnerabilities
Manda Bem Release Timeline
Manda Bem Code Analysis
Output Escaping
Manda Bem Attack Surface
REST API Routes 2
WordPress Hooks 21
Maintenance & Trust
Manda Bem Maintenance & Trust
Maintenance Signals
Community Trust
Manda Bem Alternatives
Envio Ecom
envioecom-shipping
Envio Ecom (EnvioEcom): calcula frete em tempo real no checkout com as melhores transportadoras do Brasil. EnvioEcom · envio ecom.
Check & Log Email – Easy Email Testing & Mail logging
check-email
Check & Log email allows you to test if your website is correctly sending emails . Overriding of email headers and carbon copying to another address.
RSS Aggregator by Feedzy – Feed to Post, Autoblogging, News & YouTube Video Feeds Aggregator
feedzy-rss-feeds
The most powerful WordPress RSS aggregator, helping you curate content, autoblog, import RSS & display unlimited RSS feeds within a few minutes.
WP RSS Aggregator – RSS Import, Feed to Post, Autoblogging, AI Content
wp-rss-aggregator
The #1 WordPress RSS aggregator to quickly import RSS feeds, build a news aggregator, and for easy autoblogging.
Disable Blog
disable-blog
All the power of WordPress, without a blog.
Manda Bem Developer Profile
1 plugin · 200 total installs
How We Detect Manda Bem
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/mandabem/assets/js/wc-mandabem-cart.js/wp-content/plugins/mandabem/assets/js/wc-mandabem-checkout.js/wp-content/plugins/mandabem/assets/css/wc-mandabem-checkout.css/wp-content/plugins/mandabem/assets/js/wc-mandabem-cart.js/wp-content/plugins/mandabem/assets/js/wc-mandabem-checkout.jsmandabem/assets/js/wc-mandabem-cart.js?ver=mandabem/assets/js/wc-mandabem-checkout.js?ver=mandabem/assets/css/wc-mandabem-checkout.css?ver=HTML / DOM Fingerprints
mandabem-shipping-delivery-infodata-mandabem-shipping-methoddata-mandabem-tracking-codedata-mandabem-delivery-estimatewc_mandabem_cart_paramswc_mandabem_checkout_params/wp-json/mandabem/update_rastreio/wp-json/mandabem/update_entrega