Select Estados e Cidades Brasil Security & Risk Analysis

wordpress.org/plugins/select-estados-e-cidades-brasil

O Plugin Select Estados Cidades Brasil preenche automaticamente com estados e cidades Brasileiros.

50 active installs v1.6 PHP 5.2.4+ WP 4.7+ Updated Unknown
geoipgeolocationlocalizacaolocationlocator
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Select Estados e Cidades Brasil Safe to Use in 2026?

Generally Safe

Score 100/100

Select Estados e Cidades Brasil has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The 'select-estados-e-cidades-brasil' plugin version 1.6 presents significant security concerns primarily due to its unprotected AJAX endpoints. With four AJAX handlers identified and none of them incorporating authentication or capability checks, any unauthenticated user can potentially trigger these functions. This creates a broad attack surface where malicious actors could exploit these entry points for various harmful purposes, even if no direct critical vulnerabilities are immediately apparent in the static analysis. The presence of external HTTP requests also introduces a minor risk if those external resources were to become compromised or serve malicious content, although the taint analysis does not currently indicate any critical unsanitized flows. The lack of any recorded vulnerability history, while generally a positive sign, might also be interpreted as a lack of rigorous past security auditing or a simple fortunate history, rather than an inherent guarantee of security given the identified code weaknesses.

While the plugin demonstrates good practices by exclusively using prepared statements for SQL queries, this strength is overshadowed by the critical vulnerability of unprotected AJAX actions. The relatively low percentage of properly escaped output also adds to the concern, as it could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully within those outputs. The absence of shortcodes, cron events, and REST API routes with permission issues is a positive aspect, narrowing the overall potential attack vectors. In conclusion, the plugin's security posture is weakened by its highly exposed AJAX handlers and insufficient output escaping, warranting careful consideration and immediate remediation of these unprotected entry points.

Key Concerns

  • Unprotected AJAX handlers
  • Low percentage of properly escaped output
  • External HTTP requests
Vulnerabilities
None known

Select Estados e Cidades Brasil Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Select Estados e Cidades Brasil Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
9 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

41% escaped22 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
secb_ajax (includes\mwp-secbr-scripts.php:4)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
4 unprotected

Select Estados e Cidades Brasil Attack Surface

Entry Points4
Unprotected4

AJAX Handlers 4

authwp_ajax_secb_ajaxincludes\mwp-secbr-scripts.php:2
noprivwp_ajax_secb_ajaxincludes\mwp-secbr-scripts.php:3
authwp_ajax_secb_cidadesincludes\mwp-secbr-scripts.php:14
noprivwp_ajax_secb_cidadesincludes\mwp-secbr-scripts.php:15
WordPress Hooks 3
actionadmin_menuadmin\mwp-secbr-admin.php:3
actionadmin_initadmin\mwp-secbr-admin.php:16
actionwp_footerincludes\mwp-secbr-scripts.php:42
Maintenance & Trust

Select Estados e Cidades Brasil Maintenance & Trust

Maintenance Signals

WordPress version tested6.0.11
Last updatedUnknown
PHP min version5.2.4
Downloads3K

Community Trust

Rating100/100
Number of ratings2
Active installs50
Developer Profile

Select Estados e Cidades Brasil Developer Profile

Mestres do WP

3 plugins · 200 total installs

88
trust score
Avg Security Score
92/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Select Estados e Cidades Brasil

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/select-estados-e-cidades-brasil/admin/assets/images/faviconmwp.png

HTML / DOM Fingerprints

CSS Classes
secb_class_estadosecb_class_cidade
Data Attributes
secb_class_estadosecb_class_cidade
REST Endpoints
/wp-admin/admin-ajax.php
FAQ

Frequently Asked Questions about Select Estados e Cidades Brasil