ComptaFlow by MeeTempo – French Accounting for WordPress Security & Risk Analysis

wordpress.org/plugins/comptaflow-by-meetempo

French accounting (PCG) for freelancers & small businesses. Invoicing, guided entry, automatic journal entries, VAT, FEC export (Pro).

0 active installs v1.0.4 PHP 8.0+ WP 6.0+ Updated Unknown
billingbookkeepingfrench-accountinginvoicevat-france
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is ComptaFlow by MeeTempo – French Accounting for WordPress Safe to Use in 2026?

Generally Safe

Score 100/100

ComptaFlow by MeeTempo – French Accounting for WordPress has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The plugin 'comptaflow-by-meetempo' v1.0.4 presents a generally positive security posture, with a notable lack of known vulnerabilities and a good implementation of security best practices like nonces and capability checks. The attack surface appears to be well-controlled, with no exposed AJAX handlers, REST API routes, shortcodes, or cron events without proper authentication or permission checks. The extensive use of prepared statements for SQL queries (84%) further indicates a conscious effort to prevent SQL injection vulnerabilities.

However, the static analysis does reveal areas for concern. A significant portion of output (39%) is not properly escaped, which could lead to cross-site scripting (XSS) vulnerabilities if user-supplied data is not handled carefully. Additionally, 11 out of 23 analyzed taint flows have unsanitized paths, with 6 identified as high severity. This suggests a risk of sensitive data being processed or exposed in an insecure manner, potentially allowing attackers to manipulate or access information they shouldn't. The bundling of 'dompdf' is a common practice, but it's crucial to ensure this library is kept up-to-date to avoid inheriting any known vulnerabilities.

Given the absence of historical CVEs, the plugin has a strong track record. However, the taint analysis findings are a critical reminder that even with good general practices, specific code paths can harbor significant risks. The combination of high-severity unsanitized taint flows and a substantial amount of unescaped output indicates potential weaknesses that require immediate attention and remediation.

Key Concerns

  • High severity unsanitized taint flows
  • Significant unescaped output
  • Bundled library (dompdf)
Vulnerabilities
None known

ComptaFlow by MeeTempo – French Accounting for WordPress Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

ComptaFlow by MeeTempo – French Accounting for WordPress Code Analysis

Dangerous Functions
0
Raw SQL Queries
29
158 prepared
Unescaped Output
408
627 escaped
Nonce Checks
20
Capability Checks
19
File Operations
5
External Requests
0
Bundled Libraries
1

Bundled Libraries

dompdf

SQL Query Safety

84% prepared187 total queries

Output Escaping

61% escaped1035 total outputs
Data Flows
11 unsanitized

Data Flow Analysis

23 flows11 with unsanitized paths
renderForm (src\Admin\Screens\ClientsScreen.php:161)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

ComptaFlow by MeeTempo – French Accounting for WordPress Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
actioninitcomptaflow-by-meetempo.php:39
actionadmin_post_comptaflow_mark_as_paidsrc\Admin\Actions\PaymentsActions.php:18
actionadmin_post_comptaflow_download_pdfsrc\Admin\Actions\PDFActions.php:19
actionadmin_post_comptaflow_view_pdfsrc\Admin\Actions\PDFActions.php:20
actionadmin_enqueue_scriptssrc\Admin\Menu.php:25
filtercomptaflow_transaction_row_actionssrc\Admin\Screens\FinancialScreen.php:361
actionadmin_menusrc\Bootstrap.php:18
actionadmin_initsrc\Bootstrap.php:19
actionwp_dashboard_setupsrc\Bootstrap.php:20
actionadmin_enqueue_scriptssrc\Bootstrap.php:21
actionadmin_post_comptaflow_export_balancesrc\Services\ExportHandler.php:20
actionadmin_post_comptaflow_export_journalsrc\Services\ExportHandler.php:21
actionadmin_post_comptaflow_export_grandlivresrc\Services\ExportHandler.php:22
actionadmin_post_comptaflow_export_resultatsrc\Services\ExportHandler.php:23
Maintenance & Trust

ComptaFlow by MeeTempo – French Accounting for WordPress Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedUnknown
PHP min version8.0
Downloads303

Community Trust

Rating100/100
Number of ratings2
Active installs0
Developer Profile

ComptaFlow by MeeTempo – French Accounting for WordPress Developer Profile

meetempo

2 plugins · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect ComptaFlow by MeeTempo – French Accounting for WordPress

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/comptaflow-by-meetempo/assets/css/admin-styles.css/wp-content/plugins/comptaflow-by-meetempo/assets/js/admin-script.js
Version Parameters
comptaflow-by-meetempo/assets/css/admin-styles.css?ver=comptaflow-by-meetempo/assets/js/admin-script.js?ver=

HTML / DOM Fingerprints

CSS Classes
comptaflow-settingscomptaflow-vat-franchisecomptaflow-vat-pro-upsellcomptaflow-financials-infocomptaflow-pro-ctacomptaflow-pro-feature-listcomptaflow-pro-feature-itemcomptaflow-pro-upgrade-button+3 more
HTML Comments
<!-- ComptaFlow Pro feature --><!-- ComptaFlow Pro - VAT Management --><!-- VAT declaration info for Franchise regime --><!-- VAT declaration info for CA3/CA12 regime -->+3 more
Data Attributes
data-vat-regime
FAQ

Frequently Asked Questions about ComptaFlow by MeeTempo – French Accounting for WordPress