WC Provincia Canton Distrito Security & Risk Analysis

wordpress.org/plugins/wc-provincia-canton-distrito

This plugin allows you to populate your custom states, cities, and postcodes for WooCommerce.

1K active installs v1.5.4 PHP + WP 4.7+ Updated Feb 17, 2025
cantoncitiesdistritoprovinciasstates
92
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is WC Provincia Canton Distrito Safe to Use in 2026?

Generally Safe

Score 92/100

WC Provincia Canton Distrito has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1yr ago
Risk Assessment

The "wc-provincia-canton-distrito" plugin v1.5.4 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of known CVEs and common vulnerability types suggests a history of responsible development or that the plugin has not been a significant target. Furthermore, the lack of SQL injection risks due to the use of prepared statements is a strong positive indicator. The plugin also appears to have a limited attack surface, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events that are not properly protected.

However, a significant concern arises from the output escaping. 100% of the 28 identified outputs are not properly escaped. This indicates a high risk of Cross-Site Scripting (XSS) vulnerabilities, where malicious scripts could be injected into the plugin's output, potentially impacting users or administrators. Additionally, while there is a capability check, the absence of nonce checks on any potential entry points (though none are explicitly listed as unprotected) could be a weakness if certain operations are implicitly handled. The two external HTTP requests also represent a potential, albeit minor, risk depending on the nature of those requests and the target endpoints.

Key Concerns

  • All identified outputs are not properly escaped
  • No nonce checks detected
  • Two external HTTP requests detected
Vulnerabilities
None known

WC Provincia Canton Distrito Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

WC Provincia Canton Distrito Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
28
0 escaped
Nonce Checks
0
Capability Checks
1
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

0% escaped28 total outputs
Attack Surface

WC Provincia Canton Distrito Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 13
filterwoocommerce_admin_billing_fieldsincludes\wcpcd-admin.php:32
filterwoocommerce_admin_shipping_fieldsincludes\wcpcd-admin.php:33
actionwp_enqueue_scriptsincludes\wcpcd-class.php:57
actionadmin_enqueue_scriptsincludes\wcpcd-class.php:58
actionadmin_menuincludes\wcpcd-class.php:61
actionadmin_initincludes\wcpcd-class.php:62
actionwp_headincludes\wcpcd-class.php:65
actionwoocommerce_initincludes\wcpcd-class.php:331
filterwoocommerce_statesincludes\wcpcd-misc.php:30
filterwoocommerce_default_address_fieldsincludes\wcpcd-misc.php:31
actionadmin_noticeswc-prov-cant-dist.php:62
actioninitwc-prov-cant-dist.php:76
actionbefore_woocommerce_initwc-prov-cant-dist.php:83
Maintenance & Trust

WC Provincia Canton Distrito Maintenance & Trust

Maintenance Signals

WordPress version tested6.7.5
Last updatedFeb 17, 2025
PHP min version
Downloads17K

Community Trust

Rating100/100
Number of ratings5
Active installs1K
Developer Profile

WC Provincia Canton Distrito Developer Profile

Keylor Mendoza

2 plugins · 3K total installs

91
trust score
Avg Security Score
96/100
Avg Patch Time
14 days
View full developer profile
Detection Fingerprints

How We Detect WC Provincia Canton Distrito

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/wc-provincia-canton-distrito/assets/js/prov-cant-dist.min.js/wp-content/plugins/wc-provincia-canton-distrito/assets/js/prov-cant-dist.js
Script Paths
/wp-content/plugins/wc-provincia-canton-distrito/assets/js/prov-cant-dist.min.js/wp-content/plugins/wc-provincia-canton-distrito/assets/js/prov-cant-dist.js
Version Parameters
wc-provincia-canton-distrito/assets/js/prov-cant-dist.min.js?ver=wc-provincia-canton-distrito/assets/js/prov-cant-dist.js?ver=

HTML / DOM Fingerprints

HTML Comments
<!-- WC HPOS Compatibility check -->
JS Globals
window.wcpcd_ajax
FAQ

Frequently Asked Questions about WC Provincia Canton Distrito