Attach Excel Invoice WOOC – WPSHARE247 Security & Risk Analysis

wordpress.org/plugins/attach-excel-invoice-wooc-wpshare247

Cho phép tạo file excel có nội dung hóa đơn gửi đính kèm khi gửi email đặt hàng, tải file hóa đơn, zip nhiều file hóa đơn, xuất tất cả các hóa đơn.

10 active installs v1.1 PHP 5.6+ WP 4.9+ Updated Unknown
emailinvoiceorderwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Attach Excel Invoice WOOC – WPSHARE247 Safe to Use in 2026?

Generally Safe

Score 100/100

Attach Excel Invoice WOOC – WPSHARE247 has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "attach-excel-invoice-wooc-wpshare247" v1.1 plugin presents a significant security risk due to multiple unauthenticated entry points and a lack of proper input sanitization and output escaping. The static analysis reveals two AJAX handlers that lack any form of authentication checks, meaning any user, even unauthenticated ones, could potentially trigger these functions. Furthermore, all SQL queries are executed without prepared statements, increasing the risk of SQL injection vulnerabilities. The taint analysis showing two flows with unsanitized paths, even without critical or high severity, highlights potential pathways for malicious data to be processed insecurely. The plugin also exhibits poor output escaping practices, with only 1% of outputs being properly handled, making it susceptible to cross-site scripting (XSS) attacks. The absence of vulnerability history is a positive sign, but it does not negate the immediate risks identified in the code itself. The current security posture is weak, with a substantial attack surface exposed and critical security best practices ignored.

Key Concerns

  • Unauthenticated AJAX handlers found
  • SQL queries without prepared statements
  • Lack of output escaping
  • Unsanitized paths in taint analysis
  • No nonce checks on entry points
  • No capability checks on entry points
Vulnerabilities
None known

Attach Excel Invoice WOOC – WPSHARE247 Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Attach Excel Invoice WOOC – WPSHARE247 Code Analysis

Dangerous Functions
0
Raw SQL Queries
1
0 prepared
Unescaped Output
128
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
36
External Requests
0
Bundled Libraries
0

SQL Query Safety

0% prepared1 total queries

Output Escaping

1% escaped129 total outputs
Data Flows
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
wooc_handle_bulk_actions (inc\class.helper.php:108)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
2 unprotected

Attach Excel Invoice WOOC – WPSHARE247 Attack Surface

Entry Points2
Unprotected2

AJAX Handlers 2

authwp_ajax_js_aeiwooc_download_excel_initinc\class.helper.php:11
noprivwp_ajax_js_aeiwooc_download_excel_initinc\class.helper.php:12
WordPress Hooks 11
actionplugins_loadedinc\class.helper.php:13
filterbulk_actions-edit-shop_orderinc\class.helper.php:98
filterhandle_bulk_actions-edit-shop_orderinc\class.helper.php:99
filtermanage_shop_order_posts_columnsinc\class.helper.php:151
actionmanage_shop_order_posts_custom_columninc\class.helper.php:152
actionadmin_menuinc\class.setting.page.php:13
actionadmin_initinc\class.setting.page.php:14
actionadmin_footerinc\class.setting.page.php:15
actionadmin_enqueue_scriptsinc\class.setting.page.php:16
filterplugin_action_linksinc\class.setting.page.php:17
filterwoocommerce_email_attachmentsinc\theme_functions.php:2
Maintenance & Trust

Attach Excel Invoice WOOC – WPSHARE247 Maintenance & Trust

Maintenance Signals

WordPress version tested5.5.18
Last updatedUnknown
PHP min version5.6
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs10
Developer Profile

Attach Excel Invoice WOOC – WPSHARE247 Developer Profile

Website366.com

7 plugins · 5K total installs

86
trust score
Avg Security Score
88/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Attach Excel Invoice WOOC – WPSHARE247

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/attach-excel-invoice-wooc-wpshare247/inc/assets/admin_aeiwooc.css/wp-content/plugins/attach-excel-invoice-wooc-wpshare247/inc/assets/admin_aeiwooc.js
Script Paths
/wp-content/plugins/attach-excel-invoice-wooc-wpshare247/inc/assets/admin_aeiwooc.js
Version Parameters
admin_aeiwooc_css?ver=1.0.0admin_aeiwooc_js?ver=1.0

HTML / DOM Fingerprints

CSS Classes
pro-message
Data Attributes
data-aeiwooc-field
JS Globals
Aeiwooc
FAQ

Frequently Asked Questions about Attach Excel Invoice WOOC – WPSHARE247