
Select Estados e Cidades Brasil Security & Risk Analysis
wordpress.org/plugins/select-estados-e-cidades-brasilO Plugin Select Estados Cidades Brasil preenche automaticamente com estados e cidades Brasileiros.
Is Select Estados e Cidades Brasil Safe to Use in 2026?
Generally Safe
Score 100/100Select Estados e Cidades Brasil has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The 'select-estados-e-cidades-brasil' plugin version 1.6 presents significant security concerns primarily due to its unprotected AJAX endpoints. With four AJAX handlers identified and none of them incorporating authentication or capability checks, any unauthenticated user can potentially trigger these functions. This creates a broad attack surface where malicious actors could exploit these entry points for various harmful purposes, even if no direct critical vulnerabilities are immediately apparent in the static analysis. The presence of external HTTP requests also introduces a minor risk if those external resources were to become compromised or serve malicious content, although the taint analysis does not currently indicate any critical unsanitized flows. The lack of any recorded vulnerability history, while generally a positive sign, might also be interpreted as a lack of rigorous past security auditing or a simple fortunate history, rather than an inherent guarantee of security given the identified code weaknesses.
While the plugin demonstrates good practices by exclusively using prepared statements for SQL queries, this strength is overshadowed by the critical vulnerability of unprotected AJAX actions. The relatively low percentage of properly escaped output also adds to the concern, as it could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully within those outputs. The absence of shortcodes, cron events, and REST API routes with permission issues is a positive aspect, narrowing the overall potential attack vectors. In conclusion, the plugin's security posture is weakened by its highly exposed AJAX handlers and insufficient output escaping, warranting careful consideration and immediate remediation of these unprotected entry points.
Key Concerns
- Unprotected AJAX handlers
- Low percentage of properly escaped output
- External HTTP requests
Select Estados e Cidades Brasil Security Vulnerabilities
Select Estados e Cidades Brasil Code Analysis
Output Escaping
Data Flow Analysis
Select Estados e Cidades Brasil Attack Surface
AJAX Handlers 4
WordPress Hooks 3
Maintenance & Trust
Select Estados e Cidades Brasil Maintenance & Trust
Maintenance Signals
Community Trust
Select Estados e Cidades Brasil Alternatives
Preenchimento Automatico CEP Brasil
preenchimento-automatico-cep-brasil
Preenchimento automático dos campos de endereço a partir de um CEP
Geolocation IP Detection
geoip-detect
Provides geographic information detected by an IP adress.
If-So Geolocation
if-so-geolocation
All-in-one geolocation. Personalized content, geolocation Dynamic Keyword Insertion shortcodes, Rediects, and more. No coding required!
WP Cloudflare GeoIP Redirect
wp-cloudflare-geoip-redirect
Easily setup redirect for visitors/users from selected countries to specific URL utilizing Cloudflare IP Geolocation.
DM Visitor Location Notification
dm-visitor-location-notification
DM VLN allows you to display notifications when new visitors access the page with location details and stats with top 10 countries for that page.
Select Estados e Cidades Brasil Developer Profile
3 plugins · 200 total installs
How We Detect Select Estados e Cidades Brasil
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/select-estados-e-cidades-brasil/admin/assets/images/faviconmwp.pngHTML / DOM Fingerprints
secb_class_estadosecb_class_cidadesecb_class_estadosecb_class_cidade/wp-admin/admin-ajax.php