
Another PDF invoices and Packing slips addon for WC Security & Risk Analysis
wordpress.org/plugins/byconsoleorderinvoiceCreate, print, download invoices and packing slips with delivery date time for WooCommerce orders.
Is Another PDF invoices and Packing slips addon for WC Safe to Use in 2026?
Generally Safe
Score 85/100Another PDF invoices and Packing slips addon for WC has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "byconsoleorderinvoice" plugin version 1.0.1 presents a mixed security posture. On the positive side, there are no known CVEs associated with this plugin, indicating a potentially stable security history. The static analysis reveals a remarkably small attack surface with zero identified entry points, and importantly, 100% of SQL queries utilize prepared statements. This suggests good practices in preventing common SQL injection vulnerabilities.
However, several concerns are flagged by the code analysis. A significant portion (24%) of output is not properly escaped, which could lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. Furthermore, the taint analysis indicates six flows with unsanitized paths, and while no critical or high severity issues were found in this specific analysis, the presence of unsanitized paths is a red flag that requires careful review. The complete absence of nonce and capability checks on any potential entry points (even though none were identified in this specific scan) is a fundamental security weakness, as it implies a lack of authorization and protection against CSRF or unauthorized access should new entry points be introduced or identified.
While the lack of vulnerability history is encouraging, the presence of unsanitized paths and unescaped output in the static analysis suggests potential areas of weakness. The bundled TCPDF library, while not immediately flagged as vulnerable, is a dated version and could become a target if vulnerabilities are discovered in future versions. The plugin demonstrates strengths in handling SQL but exhibits weaknesses in output escaping and authorization checks, which could be exploited if not addressed.
Key Concerns
- Unescaped output detected
- Unsanitized paths in taint analysis
- Bundled outdated library (TCPDF)
- No nonce checks
- No capability checks
Another PDF invoices and Packing slips addon for WC Security Vulnerabilities
Another PDF invoices and Packing slips addon for WC Code Analysis
Bundled Libraries
Output Escaping
Data Flow Analysis
Another PDF invoices and Packing slips addon for WC Attack Surface
WordPress Hooks 10
Maintenance & Trust
Another PDF invoices and Packing slips addon for WC Maintenance & Trust
Maintenance Signals
Community Trust
Another PDF invoices and Packing slips addon for WC Alternatives
PDF Invoices & Packing Slips for WooCommerce
woocommerce-pdf-invoices-packing-slips
Create, print & automatically email PDF or XML Invoices & PDF Packing Slips for WooCommerce orders.
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels
print-invoices-packing-slip-labels-for-woocommerce
Auto-generate and attach WooCommerce PDF invoices and packing slips to order emails with customizable templates & bulk print options.
Booster for WooCommerce – PDF Invoices, Abandoned Cart, Variation Swatches & 100+ Tools
woocommerce-jetpack
Supercharge WooCommerce with FREE Abandoned Cart Recovery, Product Variation Swatches, PDF Invoices & 100+ tools. Boost sales & save time.
Invoices for WooCommerce
woocommerce-pdf-invoices
Automatically generate and attach customizable PDF Invoices and PDF Packing Slips for WooCommerce to emails.
Flexible PDF Invoices for WooCommerce & WordPress
flexible-invoices
WooCommerce PDF invoices made simple. EU VAT validation, reverse charge invoice, proforma invoices, MOSS / OSS support, invoices in bulk and more.
Another PDF invoices and Packing slips addon for WC Developer Profile
5 plugins · 560 total installs
How We Detect Another PDF invoices and Packing slips addon for WC
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/byconsoleorderinvoice/js/admin_image_upload_custom.js/wp-content/plugins/byconsoleorderinvoice/js/admin_image_upload_custom.jsbyconsoleorderinvoice/js/admin_image_upload_custom.js?ver=byconsoleorderinvoice/css/admin_image_upload_custom.css?ver=HTML / DOM Fingerprints
bycorderinvoice_invoice_date_formatbycorderinvoice_invoice_generationbycorderinvoice_pdf_invoice_button_behaviourbycorderinvoice_print_delivery_or_pickup_date_and_timebyconsolewooodt_delivery_typebyconsolewooodt_delivery_date+1 morebyconsoleorderinvoicedir