
Virtuaria Correios – Frete, Etiqueta, Rastreio e Declaração Security & Risk Analysis
wordpress.org/plugins/virtuaria-correiosEtiqueta, declaração, rastreio, calculadora, devolução, campos de checkout, descontos, tudo isso na versão grátis, com ou sem contrato. Tem MUITO+
Is Virtuaria Correios – Frete, Etiqueta, Rastreio e Declaração Safe to Use in 2026?
Generally Safe
Score 100/100Virtuaria Correios – Frete, Etiqueta, Rastreio e Declaração has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The virtuaria-correios plugin v1.12.11 exhibits a generally good security posture, with strong adherence to best practices like prepared SQL statements and proper output escaping. The absence of known vulnerabilities in its history is a positive indicator. However, there are specific areas of concern that warrant attention.
The static analysis reveals a significant attack surface, with 18 AJAX handlers, one of which lacks authentication checks. This unprotected entry point is a critical risk. Furthermore, the taint analysis highlights two high-severity flows with unsanitized paths, suggesting potential for malicious data injection or manipulation if these paths are exploited. The presence of the bundled TCPDF library, while not explicitly flagged as vulnerable in the provided data, is a general concern as outdated bundled libraries can introduce unforeseen security risks.
Despite the robust SQL query protection and high output escaping rates, the unprotected AJAX handler and high-severity taint flows are notable weaknesses. The plugin's clean vulnerability history is reassuring, but it does not negate the risks identified in the current code analysis. Overall, the plugin demonstrates a good foundation in security but requires immediate attention to address the identified unprotected AJAX endpoint and high-severity taint flows to mitigate potential security incidents.
Key Concerns
- Unprotected AJAX handler found
- High severity taint flows with unsanitized paths
- Bundled outdated TCPDF library
Virtuaria Correios – Frete, Etiqueta, Rastreio e Declaração Security Vulnerabilities
Virtuaria Correios – Frete, Etiqueta, Rastreio e Declaração Code Analysis
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Virtuaria Correios – Frete, Etiqueta, Rastreio e Declaração Attack Surface
AJAX Handlers 18
Shortcodes 2
WordPress Hooks 93
Maintenance & Trust
Virtuaria Correios – Frete, Etiqueta, Rastreio e Declaração Maintenance & Trust
Maintenance Signals
Community Trust
Virtuaria Correios – Frete, Etiqueta, Rastreio e Declaração Alternatives
Calculadora de Frete e Campos Checkout para o Brasil
woo-better-shipping-calculator-for-brazil
Shipping calculator for Brazilian WooCommerce stores with automatic Postal Code address pre-filling and Brazilian Market on WooCommerce.
SuperFrete
superfrete
Integração com a plataforma SuperFrete para WooCommerce.
Envio Ecom
envioecom-shipping
Envio Ecom (EnvioEcom): calcula frete em tempo real no checkout com as melhores transportadoras do Brasil. EnvioEcom · envio ecom.
Claudio Sanches – Correios for WooCommerce
woocommerce-correios
Integration between the Correios and WooCommerce
Melhor Envio
melhor-envio-cotacao
Requires Wordpress 4.0+ Requires WooCommerce 4.0+ License: GPLv3 License URI: https://www.gnu.org/licenses/gpl-3.0.html Plugin para cotação e compra d …
Virtuaria Correios – Frete, Etiqueta, Rastreio e Declaração Developer Profile
10 plugins · 2K total installs
How We Detect Virtuaria Correios – Frete, Etiqueta, Rastreio e Declaração
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/virtuaria-correios/admin/js/uninstall.js/wp-content/plugins/virtuaria-correios/admin/css/uninstall.css/wp-content/plugins/virtuaria-correios/admin/js/uninstall.jsvirtuaria-correios/admin/js/uninstall.js?ver=virtuaria-correios/admin/css/uninstall.css?ver=HTML / DOM Fingerprints
data-noncedata-ajax_urlvirt_correios_uninstall/wp-json/virtuaria-correios/v1/feedback