bFatura – Invoice Fields for WooCommerce Security & Risk Analysis

wordpress.org/plugins/bfatura

Adds an invoice type switcher (Individual/Company) on WooCommerce checkout with Turkey-specific invoice fields.

0 active installs v1.0.14 PHP 7.2+ WP 5.8+ Updated Mar 1, 2026
checkoutinvoicetax-numbertcknwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is bFatura – Invoice Fields for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

bFatura – Invoice Fields for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 5mo ago
Risk Assessment

The "bfatura" plugin v1.0.14 demonstrates a strong security posture based on the provided static analysis. The absence of any identified dangerous functions, raw SQL queries, or unescaped output is commendable. Furthermore, the plugin correctly utilizes prepared statements for all SQL queries and ensures that all output is properly escaped. The presence of nonce checks, while not universally applied across all potential entry points, suggests an awareness of common web vulnerabilities.

Despite these positive indicators, the static analysis reveals a complete lack of capability checks, which is a significant concern. This means that even though nonces might be present, there are no checks to ensure that a logged-in user actually has the necessary permissions to perform actions. The absence of any identified critical or high-severity taint flows is positive, but the limited scope of the taint analysis (only 1 flow analyzed) might not be comprehensive enough to detect all potential issues. The vulnerability history being completely clear is a strong positive, indicating a lack of publicly known security flaws.

In conclusion, "bfatura" v1.0.14 exhibits good practices in terms of code hygiene and data sanitization. However, the complete omission of capability checks represents a notable weakness that could expose the plugin to privilege escalation or unauthorized actions by authenticated users. While the plugin is currently free of known vulnerabilities, the lack of permission checks warrants careful consideration and potential improvement to fully secure its functionality.

Key Concerns

  • No capability checks found
Vulnerabilities
None known

bFatura – Invoice Fields for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

bFatura – Invoice Fields for WooCommerce Release Timeline

v1.0.14Current
Code Analysis
Analyzed Apr 16, 2026

bFatura – Invoice Fields for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
0
19 escaped
Nonce Checks
3
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

100% escaped19 total outputs
Data Flows · Security
All sanitized

Data Flow Analysis

1 flows
<kurumsal-bireysel-fatura> (kurumsal-bireysel-fatura.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

bFatura – Invoice Fields for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 7
filterwoocommerce_checkout_fieldskurumsal-bireysel-fatura.php:18
filterwoocommerce_default_address_fieldskurumsal-bireysel-fatura.php:112
actionwoocommerce_checkout_processkurumsal-bireysel-fatura.php:244
actionwoocommerce_checkout_processkurumsal-bireysel-fatura.php:280
actionwoocommerce_checkout_update_order_metakurumsal-bireysel-fatura.php:328
actionwoocommerce_admin_order_data_after_billing_addresskurumsal-bireysel-fatura.php:370
actionwp_enqueue_scriptskurumsal-bireysel-fatura.php:406
Maintenance & Trust

bFatura – Invoice Fields for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedMar 1, 2026
PHP min version7.2
Downloads166

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

bFatura – Invoice Fields for WooCommerce Developer Profile

Çağrı BOLCAL

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect bFatura – Invoice Fields for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/bfatura/assets/css/bfatura.css/wp-content/plugins/bfatura/assets/js/bfatura.js
Script Paths
/wp-content/plugins/bfatura/assets/js/bfatura.js
Version Parameters
bfatura/assets/css/bfatura.css?ver=bfatura/assets/js/bfatura.js?ver=

HTML / DOM Fingerprints

CSS Classes
kurumsal-bireysel-fatura-fields
Data Attributes
data-id="kurumsal_siparis"data-id="billing_vergi_dairesi"data-id="billing_vergi_numara"data-id="billing_tc_kimlik_no"
JS Globals
bfatura_tc_validbfatura_vergi_no_validbfatura_tc_inputbfatura_vergi_no_input
FAQ

Frequently Asked Questions about bFatura – Invoice Fields for WooCommerce