PT Variants Security & Risk Analysis

wordpress.org/plugins/pt-variants

Permite ter o WordPress em português segundo o Acordo Ortográfico para a Língua Portuguesa de 1990 (ou em português informal).

10 active installs v0.1 PHP + WP 4.2.1+ Updated May 29, 2015
ao90languagepacksportuguesetranslations
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is PT Variants Safe to Use in 2026?

Generally Safe

Score 85/100

PT Variants has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 10yr ago
Risk Assessment

Based on the static analysis, the "pt-variants" plugin v0.1 exhibits a strong security posture. The absence of any identified dangerous functions, raw SQL queries, unescaped output, file operations, external HTTP requests, or critical taint flows suggests a well-written and secure codebase. Furthermore, the lack of any known vulnerabilities in its history reinforces this impression, indicating a responsible development approach.

However, the analysis reveals a complete lack of any security checks, including nonce checks and capability checks, across all entry points. While the current attack surface is reported as zero, this absence of any protective mechanisms is a significant concern. Should any new entry points be introduced in future versions, or if the current interpretation of the attack surface is incomplete, these vulnerabilities could be easily exploited. This reliance on the absence of an attack surface rather than implementing defensive coding practices presents a notable weakness.

In conclusion, the "pt-variants" plugin v0.1 is currently very secure due to its clean code and clean vulnerability history. However, its complete lack of any security checks, such as nonce and capability checks, represents a substantial risk. This oversight could lead to severe vulnerabilities if the plugin's functionality or attack surface expands in the future. The current security is fragile, relying on the absence of attack vectors rather than robust protection.

Key Concerns

  • No nonce checks implemented
  • No capability checks implemented
Vulnerabilities
None known

PT Variants Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

PT Variants Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
8 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped8 total outputs
Attack Surface

PT Variants Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 3
actionadmin_initpt-variants.php:40
actionoverride_load_textdomainpt-variants.php:46
actionadmin_initpt-variants.php:49
Maintenance & Trust

PT Variants Maintenance & Trust

Maintenance Signals

WordPress version tested4.2.39
Last updatedMay 29, 2015
PHP min version
Downloads3K

Community Trust

Rating94/100
Number of ratings3
Active installs10
Developer Profile

PT Variants Developer Profile

Marco Pereirinha

1 plugin · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect PT Variants

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

HTML / DOM Fingerprints

FAQ

Frequently Asked Questions about PT Variants