Digi Bill Security & Risk Analysis

wordpress.org/plugins/digi-bill

We’ve revolutionized conventional bill that mostly goes to a dustbin as a marketing asset. Reach your customers while in the store and improve custome …

0 active installs v1.0.3 PHP 7.2+ WP 5.2+ Updated Mar 10, 2023
billsdigibilldigital-billinvoice
85
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Digi Bill Safe to Use in 2026?

Generally Safe

Score 85/100

Digi Bill has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 3yr ago
Risk Assessment

The "digi-bill" v1.0.3 plugin exhibits a concerning security posture despite its lack of recorded historical vulnerabilities. The static analysis reveals significant weaknesses, most notably a single AJAX handler that lacks any authentication or capability checks. This represents a direct and exploitable entry point for attackers, as evidenced by the two identified taint flows with unsanitized paths, which are flagged as high severity. Furthermore, the plugin's output escaping is poor, with only 20% of outputs properly escaped, increasing the risk of cross-site scripting (XSS) vulnerabilities.

While the plugin demonstrates good practices by exclusively using prepared statements for its SQL queries and having no recorded CVEs, these strengths are overshadowed by the critical security flaws. The absence of nonce checks and capability checks on the identified AJAX handler creates a wide-open door for malicious input to be processed. The limited attack surface is a positive, but the lack of security on its sole entry point is a major concern. The absence of historical vulnerabilities could indicate a lack of targeted security research or simply that the plugin hasn't been thoroughly audited, rather than a guaranteed secure state.

In conclusion, "digi-bill" v1.0.3 is a high-risk plugin due to its unprotected AJAX endpoint and high-severity taint flows. The lack of proper authentication and sanitization on this entry point makes it susceptible to various attacks, including potential XSS and unauthorized actions. While its SQL practices are commendable and there are no known CVEs, these do not mitigate the immediate and significant risks presented by the identified code vulnerabilities.

Key Concerns

  • AJAX handler without auth checks
  • High severity unsanitized taint flows
  • Poor output escaping (20% escaped)
  • Missing nonce checks
  • Missing capability checks
Vulnerabilities
None known

Digi Bill Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Version History

Digi Bill Release Timeline

No version history available.
Code Analysis
Analyzed Apr 16, 2026

Digi Bill Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
7 prepared
Unescaped Output
4
1 escaped
Nonce Checks
0
Capability Checks
0
File Operations
0
External Requests
3
Bundled Libraries
2

Bundled Libraries

DataTablesjQuery

SQL Query Safety

100% prepared7 total queries

Output Escaping

20% escaped5 total outputs
Data Flows · Security
2 unsanitized

Data Flow Analysis

2 flows2 with unsanitized paths
digibill_ajax_handler (DigiBill.php:156)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface
1 unprotected

Digi Bill Attack Surface

Entry Points1
Unprotected1

AJAX Handlers 1

authwp_ajax_digibill_plugin_libraryDigiBill.php:154
WordPress Hooks 5
filterplugin_action_linksDigiBill.php:21
actionadmin_menuDigiBill.php:42
actioninitDigiBill.php:137
actionadmin_initDigiBill.php:143
actionwoocommerce_thankyouDigiBill.php:298
Maintenance & Trust

Digi Bill Maintenance & Trust

Maintenance Signals

WordPress version tested6.1.10
Last updatedMar 10, 2023
PHP min version7.2
Downloads740

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Digi Bill Developer Profile

Adeona Technologies

2 plugins · 10 total installs

84
trust score
Avg Security Score
85/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Digi Bill

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/digi-bill/assets/js/jquery.validate.min.js/wp-content/plugins/digi-bill/assets/js/script.js
Script Paths
/wp-content/plugins/digi-bill/assets/js/jquery.validate.min.js/wp-content/plugins/digi-bill/assets/js/script.js
Version Parameters
digi-bill/assets/js/jquery.validate.min.js?ver=digi-bill/assets/js/script.js?ver=

HTML / DOM Fingerprints

Data Attributes
data-digibill
JS Globals
digibillajaxurl
FAQ

Frequently Asked Questions about Digi Bill