Custom Invoice URL for WooCommerce by Digidopt Security & Risk Analysis

wordpress.org/plugins/custom-invoice-url-for-woo-by-digidopt

A Free one-click-to-install Custom Invoice URL for WooCommerce by Digidopt.

0 active installs v1.0.1 PHP 7.4+ WP 3.0.0+ Updated Dec 31, 2022
customgoogle-driveinvoiceonedrivewoocommerce
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Download
Safety Verdict

Is Custom Invoice URL for WooCommerce by Digidopt Safe to Use in 2026?

Generally Safe

Score 85/100

Custom Invoice URL for WooCommerce by Digidopt has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

Based on the provided static analysis and vulnerability history, the "custom-invoice-url-for-woo-by-digidopt" plugin v1.0.1 exhibits a generally strong security posture. The absence of any recorded CVEs, combined with the plugin's adherence to several WordPress security best practices like using prepared statements for SQL queries and including nonce and capability checks, suggests a commitment to secure coding. The static analysis further reinforces this by showing no dangerous functions, no file operations, and no external HTTP requests, significantly reducing the potential for common attack vectors.

However, a notable concern arises from the output escaping. With 58% of outputs properly escaped, there's a significant portion (42%) that remains unescaped. This could potentially lead to Cross-Site Scripting (XSS) vulnerabilities if user-supplied or externally sourced data is directly outputted without proper sanitization. While the taint analysis did not reveal any immediate critical or high severity flows, the unescaped output represents a latent risk that could be exploited in conjunction with other factors or if future code changes introduce exploitable taint paths.

In conclusion, the plugin demonstrates a solid foundation with robust protection against many common WordPress threats. The vulnerability history shows no past issues, which is highly encouraging. The primary area requiring attention is the incomplete output escaping, which, despite the current lack of identified high-severity issues, poses a non-negligible risk and warrants improvement to achieve a more robust security profile.

Key Concerns

  • Partial output escaping
Vulnerabilities
None known

Custom Invoice URL for WooCommerce by Digidopt Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Custom Invoice URL for WooCommerce by Digidopt Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
5
7 escaped
Nonce Checks
1
Capability Checks
1
File Operations
0
External Requests
0
Bundled Libraries
0

Output Escaping

58% escaped12 total outputs
Data Flows
All sanitized

Data Flow Analysis

1 flows
<index> (index.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Custom Invoice URL for WooCommerce by Digidopt Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 14
filterwoocommerce_order_actionsindex.php:20
actionwoocommerce_order_action_invoiceindex.php:27
filtermanage_edit-shop_order_columnsindex.php:36
actionmanage_shop_order_posts_custom_columnindex.php:43
actionadd_meta_boxesindex.php:57
actionsave_postindex.php:74
actioninitindex.php:97
filterquery_varsindex.php:103
actionwoocommerce_account_view-invoice_endpointindex.php:110
actionwoocommerce_order_details_after_order_tableindex.php:127
filterwoocommerce_my_account_my_orders_actionsindex.php:145
actionadmin_initindex.php:152
filterwoocommerce_get_settings_pagesindex.php:155
filterwoocommerce_settings_tabs_arrayindex.php:173
Maintenance & Trust

Custom Invoice URL for WooCommerce by Digidopt Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedDec 31, 2022
PHP min version7.4
Downloads1K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Custom Invoice URL for WooCommerce by Digidopt Developer Profile

digidopt

3 plugins · 50 total installs

85
trust score
Avg Security Score
87/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Custom Invoice URL for WooCommerce by Digidopt

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/custom-invoice-url-for-woo-by-digidopt/style.css/wp-content/plugins/custom-invoice-url-for-woo-by-digidopt/js/custom-invoice-url-for-woo-by-digidopt.js
Script Paths
/wp-content/plugins/custom-invoice-url-for-woo-by-digidopt/js/custom-invoice-url-for-woo-by-digidopt.js
Version Parameters
custom-invoice-url-for-woo-by-digidopt/style.css?ver=custom-invoice-url-for-woo-by-digidopt/js/custom-invoice-url-for-woo-by-digidopt.js?ver=

HTML / DOM Fingerprints

Data Attributes
name="invoice_link_woocommerce_invoice_url"id="invoice_link_woocommerce_invoice_url"name="invoice_link_woocommerce_metabox_nonce"id="invoice_link_woocommerce"
FAQ

Frequently Asked Questions about Custom Invoice URL for WooCommerce by Digidopt