Declarando – Gestión de Facturas Security & Risk Analysis

wordpress.org/plugins/declarando-gestion-facturas

Integra automáticamente tu tienda online con Declarando para gestionar facturas, sincronizar pedidos y mantener tu contabilidad al día.

300 active installs v1.0.3 PHP 7.4+ WP 5.0+ Updated Jun 10, 2026
automatizaciondeclarandofacturacionfacturaswoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Declarando – Gestión de Facturas Safe to Use in 2026?

Generally Safe

Score 100/100

Declarando – Gestión de Facturas has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 2mo ago
Risk Assessment

The plugin "declarando-gestion-facturas" v1.0.0 exhibits a mixed security posture. While it demonstrates good practices by largely using prepared statements for SQL queries and properly escaping output, significant concerns arise from its attack surface and taint analysis. The presence of one AJAX handler without authentication checks presents a direct and exploitable entry point for attackers, even without critical severity taint flows. The single unsanitized path identified in the taint analysis, while not explicitly critical, is a potential vector for injection attacks if not handled carefully. The absence of any recorded vulnerability history is a positive indicator, suggesting a generally stable codebase or a lack of prior public scrutiny. However, this lack of history should not overshadow the identified weaknesses in the current static analysis.

Overall, the plugin's strengths lie in its careful handling of database interactions and output. The primary risk stems from an exposed AJAX endpoint that could potentially be leveraged for unauthorized actions if it processes user-supplied data without proper validation and authorization. The identified unsanitized path, though not deemed critical, warrants attention to prevent potential future vulnerabilities. The plugin has a small attack surface, but one critical unprotected entry point significantly lowers its security score. A proactive approach to securing this AJAX handler is highly recommended.

Key Concerns

  • Unprotected AJAX handler
  • Flow with unsanitized path
Vulnerabilities
None known

Declarando – Gestión de Facturas Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Declarando – Gestión de Facturas Release Timeline

v1.0.3Current
v1.0.2
v1.0.1
v1.0.0
Code Analysis
Analyzed Mar 16, 2026

Declarando – Gestión de Facturas Code Analysis

Dangerous Functions
0
Raw SQL Queries
8
10 prepared
Unescaped Output
9
71 escaped
Nonce Checks
4
Capability Checks
6
File Operations
3
External Requests
2
Bundled Libraries
0

SQL Query Safety

56% prepared18 total queries

Output Escaping

89% escaped80 total outputs
Data Flows · Security
1 unsanitized

Data Flow Analysis

2 flows1 with unsanitized paths
<RefundsUIBox> (src\Admin\RefundsUIBox.php:0)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Declarando – Gestión de Facturas Attack Surface

Entry Points2
Unprotected1

AJAX Handlers 2

authwp_ajax_decl82gf_crear_facturasrc\Admin\Column.php:65
authwp_ajax_decl82gf_crear_abonosrc\Admin\RefundsUIBox.php:30
WordPress Hooks 28
actionadmin_noticesdeclarando-gestion-facturas.php:30
actionadmin_menudeclarando-gestion-facturas.php:109
actionadmin_initdeclarando-gestion-facturas.php:110
actionadmin_enqueue_scriptsdeclarando-gestion-facturas.php:111
actionadmin_post_guardar_declarando_vinculardeclarando-gestion-facturas.php:112
actionadmin_post_guardar_declarando_datosdeclarando-gestion-facturas.php:113
actionadmin_post_declarando_desvinculardeclarando-gestion-facturas.php:114
actionplugins_loadeddeclarando-gestion-facturas.php:115
actionadmin_enqueue_scriptsdeclarando-gestion-facturas.php:123
actionadmin_headdeclarando-gestion-facturas.php:195
actionadmin_enqueue_scriptssrc\Admin\Column.php:13
filtermanage_edit-shop_order_columnssrc\Admin\Column.php:18
actionmanage_shop_order_posts_custom_columnsrc\Admin\Column.php:36
filterwoocommerce_shop_order_list_table_columnssrc\Admin\Column.php:45
actionwoocommerce_shop_order_list_table_custom_columnsrc\Admin\Column.php:54
actionbefore_woocommerce_initsrc\Admin\Column.php:103
actionwoocommerce_order_status_changedsrc\Admin\Declarando_WC_Integrator.php:69
actionwoocommerce_order_status_changedsrc\Admin\Declarando_WC_Integrator.php:70
actionwoocommerce_created_refundsrc\Admin\Declarando_WC_Integrator.php:76
actionwoocommerce_refund_createdsrc\Admin\Declarando_WC_Integrator.php:77
actionwoocommerce_order_status_changedsrc\Admin\Declarando_WC_Integrator.php:85
filterwoocommerce_order_fully_refunded_statussrc\Admin\Declarando_WC_Integrator.php:96
actionadmin_enqueue_scriptssrc\Admin\Init.php:15
actionadmin_enqueue_scriptssrc\Admin\RefundsUIBox.php:17
actionadd_meta_boxessrc\Admin\RefundsUIBox.php:20
actionadmin_print_footer_scripts-post.phpsrc\Admin\RefundsUIBox.php:23
actionadmin_print_footer_scripts-post-new.phpsrc\Admin\RefundsUIBox.php:24
actionadmin_print_footer_scriptssrc\Admin\RefundsUIBox.php:27
Maintenance & Trust

Declarando – Gestión de Facturas Maintenance & Trust

Maintenance Signals

WordPress version tested6.8.6
Last updatedJun 10, 2026
PHP min version7.4
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs300
Developer Profile

Declarando – Gestión de Facturas Developer Profile

declarando

1 plugin · 300 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Declarando – Gestión de Facturas

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/declarando-gestion-facturas/assets/css/style.css/wp-content/plugins/declarando-gestion-facturas/assets/js/admin.js
Script Paths
/wp-content/plugins/declarando-gestion-facturas/assets/js/admin.js
Version Parameters
declarando-gestion-facturas/assets/css/style.css?ver=declarando-gestion-facturas/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
declarando-settings-sectiondeclarando-option-fielddeclarando-vincular-btndeclarando-desvincular-btn
HTML Comments
<!-- Declarando Options --><!-- Declarando API Settings -->
Data Attributes
data-declarando-option-keydata-declarando-field-name
JS Globals
window.declarandoApiSettingsvar declarandoAdminParams
REST Endpoints
/wp-json/declarando/v1/settings/wp-json/declarando/v1/sync
FAQ

Frequently Asked Questions about Declarando – Gestión de Facturas