[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$f6rozC6jdq0kMXlcQzMYh_ZD_PEreZ_Sq_H5q90Nlm5Q":3},{"slug":4,"name":5,"version":6,"author":7,"author_profile":8,"description":9,"short_description":10,"active_installs":11,"downloaded":12,"rating":13,"num_ratings":14,"last_updated":15,"tested_up_to":16,"requires_at_least":17,"requires_php":18,"tags":19,"homepage":25,"download_link":26,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30,"vulnerabilities":31,"developer":32,"crawl_stats":29,"alternatives":38,"analysis":60,"fingerprints":131},"mascaras-para-cf7","Mascaras CF7","0.5","Murilo Pinto Pereira","https:\u002F\u002Fprofiles.wordpress.org\u002Fmurilo-pinto-pereira\u002F","\u003Cp>Insere uma máscara de telefone no formato Brasileiro ou Americano, tanto com 8 quanto com 9 dígitos.\u003Cbr \u002F>\nFormato 8 Digito: (11) 1111-1111\u003Cbr \u002F>\nFormato 9 Digito: (11) 11111-1111\u003Cbr \u002F>\nFormato Americano: (111) 111-1111\u003Cbr \u002F>\nFormato Americano: 111-111-1111\u003C\u002Fp>\n\u003Cp>Insere também Máscaras de CPF, CNPJ, CEP e Dinheiro.\u003C\u002Fp>\n\u003Cp>Créditos\u003Cbr \u002F>\nForam utilizados os seguintes scripts\u002Fserviços de terceiros:\u003Cbr \u002F>\njQuery Mask Plugin (github.com\u002Figorescobar\u002FjQuery-Mask-Plugin).\u003C\u002Fp>\n","Adicione máscaras de telefone, CPF, CNPJ, CEP e Dinheiro nos campos do Contact Form 7, Elementor e outros tipos de formulários.",1000,11900,100,5,"2023-01-14T23:29:00.000Z","6.0.0","4.6","5.2.4",[20,21,22,23,24],"mascara-contact-form-7","mascara-elementor","mascara-formulario","mascara-telefone","telefone-cf7","https:\u002F\u002Fmurilopereira.com.br\u002Fplugins\u002Fplugin-mascaras-cf7\u002F","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fmascaras-para-cf7.zip",85,0,null,"2026-03-15T15:16:48.613Z",[],{"slug":33,"display_name":7,"profile_url":8,"plugin_count":34,"total_installs":11,"avg_security_score":27,"avg_patch_time_days":35,"trust_score":36,"computed_at":37},"murilo-pinto-pereira",1,30,84,"2026-04-04T14:03:34.580Z",[39],{"slug":40,"name":41,"version":42,"author":43,"author_profile":44,"description":45,"short_description":46,"active_installs":47,"downloaded":48,"rating":47,"num_ratings":49,"last_updated":50,"tested_up_to":51,"requires_at_least":52,"requires_php":53,"tags":54,"homepage":58,"download_link":59,"security_score":27,"vuln_count":28,"unpatched_count":28,"last_vuln_date":29,"fetched_at":30},"cf7-telefone","CF7 Telefone","1.0","lucascaires","https:\u002F\u002Fprofiles.wordpress.org\u002Flucascaires\u002F","\u003Cp>Insere uma máscara de telefone no formato Brasileiro, tanto com 8 quanto com 9 dígitos.\u003Cbr \u002F>\nFormato 8 Digito: (11) 1111-1111\u003Cbr \u002F>\nFormato 9 Digito: (11) 11111-1111\u003C\u002Fp>\n","Plugin do WordPress que adiciona máscara nos campos de telefone do Contact Form 7",20,2303,4,"2016-04-13T19:28:00.000Z","4.5.33","3.0","",[55,56,57,23,24],"cf7-mask","contact-form-tel","contact-form-telefone","https:\u002F\u002Fgithub.com\u002Flucascaires\u002Fcf7-telefone","https:\u002F\u002Fdownloads.wordpress.org\u002Fplugin\u002Fcf7-telefone.zip",{"attackSurface":61,"codeSignals":95,"taintFlows":106,"riskAssessment":125,"analyzedAt":130},{"hooks":62,"ajaxHandlers":91,"restRoutes":92,"shortcodes":93,"cronEvents":94,"entryPointCount":28,"unprotectedCount":28},[63,69,71,73,77,81,86],{"type":64,"name":65,"callback":66,"file":67,"line":68},"action","wp_enqueue_scripts","cf_telefone_scripts","cf7-mascaras.php",43,{"type":64,"name":65,"callback":66,"file":67,"line":70},48,{"type":64,"name":65,"callback":66,"file":67,"line":72},53,{"type":64,"name":74,"callback":75,"file":67,"line":76},"plugins_loaded","myplugin_load_textdomain",88,{"type":64,"name":78,"callback":79,"file":67,"line":80},"admin_menu","criarMenu",105,{"type":82,"name":83,"callback":84,"file":67,"line":85},"filter","init","adicionaMascaras",108,{"type":82,"name":87,"callback":88,"priority":89,"file":67,"line":90},"plugin_action_links","MascarasCF7_plugin_action_links",10,110,[],[],[],[],{"dangerousFunctions":96,"sqlUsage":97,"outputEscaping":99,"fileOperations":28,"externalRequests":28,"nonceChecks":34,"capabilityChecks":34,"bundledLibraries":105},[],{"prepared":28,"raw":28,"locations":98},[],{"escaped":34,"rawEcho":34,"locations":100},[101],{"file":102,"line":103,"context":104},"mascaras-cf7-config.php",27,"raw output",[],[107],{"entryPoint":108,"graph":109,"unsanitizedCount":28,"severity":124},"\u003Cmascaras-cf7-config> (mascaras-cf7-config.php:0)",{"nodes":110,"edges":121},[111,116],{"id":112,"type":113,"label":114,"file":102,"line":115},"n0","source","$_POST['mask_phone']",16,{"id":117,"type":118,"label":119,"file":102,"line":115,"wp_function":120},"n1","sink","update_option() [Settings Manipulation]","update_option",[122],{"from":112,"to":117,"sanitized":123},true,"low",{"summary":126,"deductions":127},"The plugin \"mascaras-para-cf7\" v0.5 exhibits a strong security posture based on the provided static analysis. The absence of any detected AJAX handlers, REST API routes, shortcodes, or cron events with unprotected entry points indicates a minimal attack surface.  The code also demonstrates good development practices, with no dangerous functions identified, all SQL queries utilizing prepared statements, and a single instance of a nonce and capability check. This suggests a conscious effort by the developer to implement security best practices.\n\nWhile the static analysis reveals no critical or high severity taint flows and an absence of known vulnerabilities in its history, the output escaping is not fully robust, with 50% of outputs being properly escaped. This means there's a theoretical possibility of cross-site scripting (XSS) vulnerabilities if the unescaped outputs are user-controlled. However, given the extremely limited attack surface and lack of other identified security flaws, the immediate risk is low. The plugin's vulnerability history being entirely clear is a positive sign, suggesting a history of secure development and maintenance.",[128],{"reason":129,"points":49},"Half of outputs not properly escaped","2026-03-16T18:45:28.390Z",{"wat":132,"direct":148},{"assetPaths":133,"generatorPatterns":140,"scriptPaths":141,"versionParams":142},[134,135,136,137,138,139],"\u002Fwp-content\u002Fplugins\u002Fmascaras-para-cf7\u002Fjs\u002Fjquery.mask.min.js","\u002Fwp-content\u002Fplugins\u002Fmascaras-para-cf7\u002Fcss\u002Fstyle.css","\u002Fwp-content\u002Fplugins\u002Fmascaras-para-cf7\u002Fjs\u002Fcf7-masks.js","\u002Fwp-content\u002Fplugins\u002Fmascaras-para-cf7\u002Fjs\u002Fcf7-telefone-us.js","\u002Fwp-content\u002Fplugins\u002Fmascaras-para-cf7\u002Fjs\u002Fcf7-telefone-us2.js","\u002Fwp-content\u002Fplugins\u002Fmascaras-para-cf7\u002Fjs\u002Fcf7-telefone.js",[],[134,136,137,138,139],[143,144,145,146,147],"mascaras-para-cf7\u002Fcss\u002Fstyle.css?ver=1.0.0","mascaras-para-cf7\u002Fjs\u002Fcf7-masks.js?ver=1.0.1","mascaras-para-cf7\u002Fjs\u002Fcf7-telefone-us.js?ver=1.0.0","mascaras-para-cf7\u002Fjs\u002Fcf7-telefone-us2.js?ver=1.0.0","mascaras-para-cf7\u002Fjs\u002Fcf7-telefone.js?ver=1.0.3",{"cssClasses":149,"htmlComments":150,"htmlAttributes":151,"restEndpoints":152,"jsGlobals":153,"shortcodeOutput":154},[],[],[],[],[],[]]