Preenchimento Automatico CEP Brasil Security & Risk Analysis

wordpress.org/plugins/preenchimento-automatico-cep-brasil

Preenchimento automático dos campos de endereço a partir de um CEP

100 active installs v1.5 PHP 5.2.4+ WP 4.7+ Updated May 30, 2022
geoipgeolocationlocalizacaolocationlocator
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Preenchimento Automatico CEP Brasil Safe to Use in 2026?

Generally Safe

Score 85/100

Preenchimento Automatico CEP Brasil has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "preenchimento-automatico-cep-brasil" v1.5 plugin exhibits a concerning security posture primarily due to its unprotected entry points. The static analysis reveals two AJAX handlers, both of which lack authentication checks. This creates a significant attack surface, allowing any unauthenticated user to potentially trigger these handlers. While the plugin performs well in other areas, such as using prepared statements for SQL queries and a high percentage of properly escaped output, the absence of authorization on its AJAX endpoints is a critical weakness.

The taint analysis shows two flows with unsanitized paths. Although these are not classified as critical or high severity, the presence of unsanitized paths in conjunction with unprotected AJAX handlers suggests a potential for cross-site scripting (XSS) or other injection vulnerabilities if user input is directly processed without proper sanitization. The plugin's vulnerability history is clean, with no recorded CVEs, which is a positive sign. However, this can sometimes be a result of limited security scrutiny rather than inherent robustness.

In conclusion, while "preenchimento-automatico-cep-brasil" v1.5 demonstrates good practices in areas like SQL and output handling, the unprotected AJAX endpoints and the identified unsanitized taint flows present a notable risk. The lack of authorization on these entry points is a fundamental security oversight that needs immediate attention to mitigate potential exploitation.

Key Concerns

  • Unprotected AJAX handlers (2)
  • Taint flows with unsanitized paths (2)
  • No nonce checks on AJAX handlers
  • No capability checks on AJAX handlers
  • Less than 100% output escaping
Vulnerabilities
None known

Preenchimento Automatico CEP Brasil Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Preenchimento Automatico CEP Brasil Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
12
49 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
1
Bundled Libraries
0

Output Escaping

80% escaped61 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
pacepbr_ajax (includes\mwp-pacwp-scripts.php:5)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Preenchimento Automatico CEP Brasil Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_pacepbr_ajaxincludes\mwp-pacwp-scripts.php:3
noprivwp_ajax_pacepbr_ajaxincludes\mwp-pacwp-scripts.php:4
WordPress Hooks 5
actionadmin_menuadmin\mwp-pacwp-admin.php:3
actionadmin_initadmin\mwp-pacwp-admin.php:17
filterum_dequeue_select2_scriptsincludes\mwp-pacwp-hooks.php:2
actionwp_enqueue_scriptsincludes\mwp-pacwp-hooks.php:3
actionwp_footerincludes\mwp-pacwp-scripts.php:12
Maintenance & Trust

Preenchimento Automatico CEP Brasil Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedMay 30, 2022
PHP min version5.2.4
Downloads4K

Community Trust

Rating100/100
Number of ratings2
Active installs100
Developer Profile

Preenchimento Automatico CEP Brasil Developer Profile

Mestres do WP

3 plugins · 200 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Preenchimento Automatico CEP Brasil

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/preenchimento-automatico-cep-brasil/includes/mwp-pacwp-scripts.php/wp-content/plugins/preenchimento-automatico-cep-brasil/admin/mwp-pacwp-admin.php/wp-content/plugins/preenchimento-automatico-cep-brasil/includes/mwp-pacwp-hooks.php

HTML / DOM Fingerprints

Data Attributes
pacepbr_class_ceppacepbr_class_logradouropacepbr_class_numeropacepbr_class_complementopacepbr_class_bairropacepbr_class_cidade+1 more
JS Globals
pacepbr_ajaxpacepbr_limpa_formulário_cep
REST Endpoints
/wp-json/pacepbr/v1/ajax
FAQ

Frequently Asked Questions about Preenchimento Automatico CEP Brasil