
WebCourier Plugin Security & Risk Analysis
wordpress.org/plugins/webcourierPlugin feito para envio de pesquisas de satisfação.
Is WebCourier Plugin Safe to Use in 2026?
Generally Safe
Score 85/100WebCourier Plugin has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The webcourier plugin v2.3 exhibits a mixed security posture. On the positive side, it demonstrates good practices by using prepared statements for all SQL queries and avoiding external HTTP requests, which significantly reduces common attack vectors. The absence of any recorded vulnerabilities in its history is also a strong indicator of developer diligence and a relatively secure codebase over time. However, the static analysis reveals several concerning areas. A significant portion of output (76%) is not properly escaped, posing a risk of Cross-Site Scripting (XSS) vulnerabilities. The plugin also lacks any nonce checks or capability checks, which are crucial for securing entry points, especially given the presence of 6 shortcodes. Furthermore, the taint analysis indicates that all analyzed flows involve unsanitized paths, although they are not currently flagged as critical or high severity. This suggests a potential for insecure file operations or path manipulation, even if no immediate high-impact vulnerabilities are apparent in this version.
Key Concerns
- Significant amount of unescaped output
- No nonce checks implemented
- No capability checks implemented
- Taint analysis shows unsanitized paths
- File operations present without sanitization checks
WebCourier Plugin Security Vulnerabilities
WebCourier Plugin Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
WebCourier Plugin Attack Surface
Shortcodes 6
WordPress Hooks 12
Maintenance & Trust
WebCourier Plugin Maintenance & Trust
Maintenance Signals
Community Trust
WebCourier Plugin Alternatives
Campaign Monitor Dual Registration
campaign-monitor-dual-registration
Automatically add new Wordpress users to your mailing list on Campaign Monitor.
New User Approve
new-user-approve
WordPress user approval plugin to moderate registrations. Approve or deny real users and prevent fake signups to control who registers on site.
User Access Manager
user-access-manager
With the "User Access Manager"-plugin you can manage the access to your posts, pages and files.
Delete Me
delete-me
Allow users with specific WordPress roles to delete themselves from the Your Profile page or anywhere Shortcodes can be used.
WP Approve User
wp-approve-user
Adds action links to user table to approve or unapprove user registrations.
WebCourier Plugin Developer Profile
1 plugin · 10 total installs
How We Detect WebCourier Plugin
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/webcourier/css/styles.css/wp-content/plugins/webcourier/js/pesquisa-add.js/wp-content/plugins/webcourier/js/angular.min.js/wp-content/plugins/webcourier/js/ControllerPesquisaAdd.js/wp-content/plugins/webcourier/js/ControllerPesquisaList.js/wp-content/plugins/webcourier/js/jquery.smartWizard.js/wp-content/plugins/webcourier/js/pesquisaAddWizard.js/wp-content/plugins/webcourier/js/sweetalert.min.js+1 moreHTML / DOM Fingerprints
edit_search[webcourier_page_config][webcourier_page_pesquisa][webcourier_page_configuracoes][webcourier_send_pesquisa]