
Checkmate PDF — Fully Customizable PDF Invoices & Packing Slips for WooCommerce Security & Risk Analysis
wordpress.org/plugins/checkmate-pdf-invoicesCreate custom PDF Invoices and Packing Slips for WooCommerce. Includes a Visual Template Editor, HPOS support, Bulk Actions, and Email Attachments.
Is Checkmate PDF — Fully Customizable PDF Invoices & Packing Slips for WooCommerce Safe to Use in 2026?
Generally Safe
Score 100/100Checkmate PDF — Fully Customizable PDF Invoices & Packing Slips for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "checkmate-pdf-invoices" plugin v2.0.3 exhibits a generally strong security posture, with a significant emphasis on secure coding practices. The absence of any recorded CVEs, including critical and high severity vulnerabilities, is a positive indicator. The plugin demonstrates good use of prepared statements for SQL queries (91%) and proper output escaping (87%), which are crucial for preventing common web application attacks. Additionally, the presence of numerous nonce and capability checks on its AJAX handlers suggests an effort to validate user permissions and prevent CSRF attacks. However, a few areas warrant attention. The presence of the `unserialize` function is a known risk if not handled with extreme caution, as unserialized data from untrusted sources can lead to code execution vulnerabilities. The taint analysis revealing 5 high severity flows with unsanitized paths, despite no publicly disclosed vulnerabilities, indicates potential internal risks that could be exploited by a skilled attacker. These unsanitized paths are the most significant concern within the code analysis, highlighting areas where user-supplied data might not be adequately validated before being used in potentially sensitive operations. The plugin's attack surface is confined to AJAX handlers, and all are reported to have authentication checks, which is commendable.
Key Concerns
- High severity taint flows with unsanitized paths
- Presence of unserialize function
Checkmate PDF — Fully Customizable PDF Invoices & Packing Slips for WooCommerce Security Vulnerabilities
Checkmate PDF — Fully Customizable PDF Invoices & Packing Slips for WooCommerce Code Analysis
Dangerous Functions Found
Bundled Libraries
SQL Query Safety
Output Escaping
Data Flow Analysis
Checkmate PDF — Fully Customizable PDF Invoices & Packing Slips for WooCommerce Attack Surface
AJAX Handlers 9
WordPress Hooks 20
Maintenance & Trust
Checkmate PDF — Fully Customizable PDF Invoices & Packing Slips for WooCommerce Maintenance & Trust
Maintenance Signals
Community Trust
Checkmate PDF — Fully Customizable PDF Invoices & Packing Slips for WooCommerce Alternatives
Print Invoice & Delivery Notes for WooCommerce
woocommerce-delivery-notes
Create and print PDF invoices, delivery notes and receipts for your WooCommerce orders. Choose your document format from multiple templates.
WebToffee WooCommerce PDF Invoices, Packing Slips, Delivery Notes & Shipping Labels
print-invoices-packing-slip-labels-for-woocommerce
Auto-generate and attach WooCommerce PDF invoices and packing slips to order emails with customizable templates & bulk print options.
Invoices for WooCommerce
woocommerce-pdf-invoices
Automatically generate and attach customizable PDF Invoices and PDF Packing Slips for WooCommerce to emails.
PDF Invoices & Packing Slips for WooCommerce – Challan
webappick-pdf-invoice-for-woocommerce
WooCommerce PDF invoice generator with automatic email attachment. Create packing slips, shipping labels, credit notes, multilingual.
PDF Invoices and Packing Slips For WooCommerce
pdf-invoices-and-packing-slips-for-woocommerce
WooCommerce PDF Invoice plugin helps to generate custom designed invoices for a WooCommerce store. Apart from the Invoice, this plugin can also be use …
Checkmate PDF — Fully Customizable PDF Invoices & Packing Slips for WooCommerce Developer Profile
5 plugins · 11K total installs
How We Detect Checkmate PDF — Fully Customizable PDF Invoices & Packing Slips for WooCommerce
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/checkmate-pdf-invoices/build/admin.css/wp-content/plugins/checkmate-pdf-invoices/build/admin.js/wp-content/plugins/checkmate-pdf-invoices/build/frontend.css/wp-content/plugins/checkmate-pdf-invoices/build/frontend.js/wp-content/plugins/checkmate-pdf-invoices/build/admin.js/wp-content/plugins/checkmate-pdf-invoices/build/frontend.jscheckmate-pdf-invoices/build/admin.css?ver=checkmate-pdf-invoices/build/admin.js?ver=checkmate-pdf-invoices/build/frontend.css?ver=checkmate-pdf-invoices/build/frontend.js?ver=HTML / DOM Fingerprints
checkmate-pdf-invoices-admin-wrappercheckmate-pdf-invoices-template-editor-container<!-- Admin menu and dashboard handler --><!-- Singleton instance --><!-- Get singleton instance --><!-- Constructor -->+8 moredata-checkmate-template-iddata-checkmate-preset-idwindow.checkmatePdfConfig/wp-json/checkmate-pdf-invoices/v1/templates/wp-json/checkmate-pdf-invoices/v1/templates/(?P<id>\d+)/wp-json/checkmate-pdf-invoices/v1/settings/wp-json/checkmate-pdf-invoices/v1/settings/(?P<key>\w+)