
Melhor Envio Security & Risk Analysis
wordpress.org/plugins/melhor-envio-cotacaoRequires Wordpress 4.0+ Requires WooCommerce 4.0+ License: GPLv3 License URI: https://www.gnu.org/licenses/gpl-3.0.html Plugin para cotação e compra d …
Is Melhor Envio Safe to Use in 2026?
Generally Safe
Score 98/100Melhor Envio has a strong security track record. Known vulnerabilities have been patched promptly.
The "melhor-envio-cotacao" v2.15.18 plugin exhibits a mixed security posture. While it excels in output escaping and SQL query preparation, significant concerns arise from its large attack surface, particularly the numerous unprotected AJAX handlers. The presence of the `unserialize` function, a known source of vulnerabilities if not handled with extreme care, combined with two taint flows with unsanitized paths, warrants close attention. Although there are no currently unpatched vulnerabilities, the historical CVEs, classified as medium severity and related to exposure of sensitive information and improper authorization, suggest a pattern of past security weaknesses that could re-emerge. The plugin demonstrates strengths in output sanitization and data querying but falters in its access control for AJAX endpoints and handling of potentially dangerous functions.
Key Concerns
- 42 unprotected AJAX handlers
- Use of unserialize function
- 2 unsanitized path taint flows
- 2 past medium severity CVEs
- Only 2 capability checks for 44 entry points
Melhor Envio Security Vulnerabilities
CVEs by Year
Severity Breakdown
2 total CVEs
Melhor Envio <= 2.15.11 - Unauthenticated Sensitive Information Exposure via Hardcoded Hash
Melhor Envio <= 2.11.19 - Cross-Site Request Forgery and Authenticated Settings Change
Melhor Envio Code Analysis
Dangerous Functions Found
SQL Query Safety
Output Escaping
Data Flow Analysis
Melhor Envio Attack Surface
AJAX Handlers 42
Shortcodes 2
WordPress Hooks 27
Maintenance & Trust
Melhor Envio Maintenance & Trust
Maintenance Signals
Community Trust
Melhor Envio Alternatives
SuperFrete
superfrete
Integração com a plataforma SuperFrete para WooCommerce.
Virtuaria Correios – Frete, Etiqueta, Rastreio e Declaração
virtuaria-correios
Etiqueta, declaração, rastreio, calculadora, devolução, campos de checkout, descontos, tudo isso na versão grátis, com ou sem contrato. Tem MUITO+
Andreani WooCommerce
andreani-shipping
Plugin oficial de Andreani para envíos en WooCommerce.
DrEnvio for WooCommerce
drenvio-for-woocommerce
Permite que tus clientes coticen por más de 10 paqueterías desde el checkout de tu tienda y con esto aumenta tu conversión.
Analix Shipping Calculator for Total Express
analix-shipping-calculator-for-total-express
O plugin Analix Shipping Calculator for Total Express integra os cálculos de frete da Total Express como um método de envio nativo do WooCommerce.
Melhor Envio Developer Profile
1 plugin · 20K total installs
How We Detect Melhor Envio
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/melhor-envio-cotacao/assets/css/admin.css/wp-content/plugins/melhor-envio-cotacao/assets/css/frontend.css/wp-content/plugins/melhor-envio-cotacao/assets/js/admin.js/wp-content/plugins/melhor-envio-cotacao/assets/js/frontend.js/wp-content/plugins/melhor-envio-cotacao/assets/js/scripts.js/wp-content/plugins/melhor-envio-cotacao/assets/js/admin.js/wp-content/plugins/melhor-envio-cotacao/assets/js/frontend.js/wp-content/plugins/melhor-envio-cotacao/assets/js/scripts.jsmelhor-envio-cotacao/assets/css/admin.css?ver=melhor-envio-cotacao/assets/css/frontend.css?ver=melhor-envio-cotacao/assets/js/admin.js?ver=melhor-envio-cotacao/assets/js/frontend.js?ver=melhor-envio-cotacao/assets/js/scripts.js?ver=HTML / DOM Fingerprints
melhor-envio-shipping-method-titlemelhor-envio-calculator-containermelhor-envio-shipping-optionsmelhor-envio-shipping-option-itemmelhor-envio-shipping-option-detailsmelhor-envio-shipping-method-detailsmelhor-envio-custom-fieldsmelhor-envio-notice+3 more<!-- melhor envio --><!-- aqui começa o widget de cotação melhor envio --><!-- aqui termina o widget de cotação melhor envio -->data-melhor-envio-plugindata-melhor-envio-calculator-optionsdata-melhor-envio-product-iddata-melhor-envio-shipping-methodmelhorEnvioDatamelhorEnvioME/wp-json/melhor-envio/v1/calculate/wp-json/melhor-envio/v1/shipping-methods[melhor_envio_calculator][melhor_envio_tracking]