ASPL Email PDF Invoice Security & Risk Analysis

wordpress.org/plugins/aspl-email-pdf-invoice

Using this plugin you can send the invoice PDF automatically with the order confirmation mail sent to the customer.

0 active installs v1.1.0 PHP 5.2+ WP 5.1+ Updated Jul 7, 2020
emailinvoiceinvoice-emailwoocommerce-invoice
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ASPL Email PDF Invoice Safe to Use in 2026?

Generally Safe

Score 85/100

ASPL Email PDF Invoice has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5yr ago
Risk Assessment

The ASPL Email PDF Invoice plugin v1.1.0 exhibits a generally good security posture based on the provided static analysis and vulnerability history. The absence of any known CVEs, critical taint flows, or direct SQL injection vulnerabilities is highly positive. The plugin also demonstrates good practices by using prepared statements for all SQL queries and performing nonce checks. However, there are areas for improvement. The low percentage of properly escaped output (54%) is a concern, as it could lead to cross-site scripting (XSS) vulnerabilities if malicious data is not sanitized before being displayed to users. Additionally, the use of the `ini_set` function, while not inherently a vulnerability, can sometimes be a signal for potential misconfigurations or unintended modifications of PHP settings if not handled with extreme care. The plugin's attack surface is currently zero, which is excellent, but this could change with future updates. Overall, while the plugin has a strong foundation, the unescaped output represents the most significant immediate risk.

Key Concerns

  • Low percentage of properly escaped output
  • Use of 'ini_set' function
Vulnerabilities
None known

ASPL Email PDF Invoice Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

ASPL Email PDF Invoice Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

ASPL Email PDF Invoice Code Analysis

Dangerous Functions
1
Raw SQL Queries
0
0 prepared
Unescaped Output
6
7 escaped
Nonce Checks
1
Capability Checks
0
File Operations
23
External Requests
0
Bundled Libraries
0

Dangerous Functions Found

ini_setini_set('log_errors', '0');include/fpdf/makefont/makefont.php:429

Output Escaping

54% escaped13 total outputs
Attack Surface

ASPL Email PDF Invoice Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 8
actionadmin_enqueue_scriptsaspl_email_pdf_invoice.php:34
actionadmin_menuaspl_email_pdf_invoice.php:40
actionadd_meta_boxesaspl_email_pdf_invoice.php:51
actioninitaspl_email_pdf_invoice.php:79
filterpage_templateaspl_email_pdf_invoice.php:101
filterwoocommerce_email_attachmentsaspl_email_pdf_invoice.php:114
filterwoocommerce_account_orders_columnsaspl_email_pdf_invoice.php:242
actionwoocommerce_my_account_my_orders_column_order-pdfaspl_email_pdf_invoice.php:268
Maintenance & Trust

ASPL Email PDF Invoice Maintenance & Trust

Maintenance Signals

WordPress version tested5.3.21
Last updatedJul 7, 2020
PHP min version5.2
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

ASPL Email PDF Invoice Developer Profile

acespritech

10 plugins · 30 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ASPL Email PDF Invoice

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/aspl-email-pdf-invoice/css/aspl_pips_custom_css.css

HTML / DOM Fingerprints

CSS Classes
aspl_pips_pdf_meta_mainaspl_pdf_a_button
FAQ

Frequently Asked Questions about ASPL Email PDF Invoice