Corrispettivi for WooCommerce Security & Risk Analysis

wordpress.org/plugins/corrispettivi-for-woocommerce

Un aiuto per la compilazione del Registro dei Corrispettivi derivanti da vendite WooCommerce.

100 active installs v0.8.4 PHP 8.0+ WP 4.4+ Updated Feb 22, 2026
corrispettivildavregistro-dei-corrispettiviwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Corrispettivi for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Corrispettivi for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The "corrispettivi-for-woocommerce" plugin version 0.8.4 exhibits a generally strong security posture based on the static analysis. It demonstrates good practices by utilizing prepared statements for all SQL queries and properly escaping a high percentage of its outputs. The absence of file operations, external HTTP requests, and a small, protected attack surface are all positive indicators. Furthermore, the lack of any known vulnerabilities in its history suggests a well-maintained and secure plugin.

However, the primary concern lies in the absence of capability checks for its single AJAX handler. While a nonce check is present, relying solely on a nonce without verifying user privileges means that any authenticated user, regardless of their role or permissions, could potentially trigger this AJAX action. This presents a potential weakness if the AJAX handler performs sensitive operations. The static analysis also noted no critical or high severity taint flows, reinforcing the idea that significant vulnerabilities are unlikely, but the lack of capability checks remains an oversight.

In conclusion, the plugin is commendably secure in many aspects, particularly regarding data handling and its limited attack surface. The absence of historical vulnerabilities is a significant strength. The sole weakness identified is the lack of capability checks on its AJAX endpoint, which, while not an immediate critical flaw given the other safeguards, should be addressed to ensure a more robust security model.

Key Concerns

  • AJAX handler without capability check
Vulnerabilities
None known

Corrispettivi for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

Corrispettivi for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
4 prepared
Unescaped Output
1
37 escaped
Nonce Checks
1
Capability Checks
0
File Operations
0
External Requests
0
Bundled Libraries
0

SQL Query Safety

100% prepared4 total queries

Output Escaping

97% escaped38 total outputs
Data Flows
All sanitized

Data Flow Analysis

2 flows
invoice_list (corrispettivi-for-woocommerce.php:240)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Corrispettivi for WooCommerce Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_corrispettivi_for_woocommerce_dismiss_noticecorrispettivi-for-woocommerce.php:62
WordPress Hooks 4
actioninitcorrispettivi-for-woocommerce.php:54
actionadmin_noticescorrispettivi-for-woocommerce.php:57
actionadmin_menucorrispettivi-for-woocommerce.php:61
actionbefore_woocommerce_initcorrispettivi-for-woocommerce.php:68
Maintenance & Trust

Corrispettivi for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 22, 2026
PHP min version8.0
Downloads3K

Community Trust

Rating40/100
Number of ratings1
Active installs100
Developer Profile

Corrispettivi for WooCommerce Developer Profile

labdav

4 plugins · 5K total installs

89
trust score
Avg Security Score
93/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Corrispettivi for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/corrispettivi-for-woocommerce/corrispettivi-for-woocommerce.php/wp-content/plugins/corrispettivi-for-woocommerce/languages/corrispettivi-for-woocommerce.pot

HTML / DOM Fingerprints

Data Attributes
corrispettivi_for_woocommerce_wc_statuscorrispettivi_for_woocommerce_dismiss_notice
FAQ

Frequently Asked Questions about Corrispettivi for WooCommerce