
Document & Data Automation Security & Risk Analysis
wordpress.org/plugins/document-data-automationGenerate dynamical documents and contracts from user input and Office templates
Is Document & Data Automation Safe to Use in 2026?
Generally Safe
Score 91/100Document & Data Automation has a strong security track record. Known vulnerabilities have been patched promptly. It's a solid choice for most WordPress installations.
The document-data-automation plugin version 1.6.2 presents a mixed security profile. On the positive side, the plugin demonstrates good practices by exclusively using prepared statements for SQL queries and includes a decent number of nonce and capability checks, indicating some awareness of security principles. Furthermore, the absence of critical or high severity taint flows and unpatched CVEs is reassuring.
However, there are notable areas for improvement. The most significant concern is the low percentage of properly escaped output (16%). This leaves the plugin vulnerable to Cross-Site Scripting (XSS) attacks, where malicious scripts could be injected and executed within the WordPress environment. The presence of a single external HTTP request also introduces a potential vector for supply chain attacks or data exfiltration if not handled with utmost care. While there are no unpatched vulnerabilities currently, the plugin has a history of medium severity vulnerabilities, specifically CSRF, which suggests a recurring need for robust security auditing and patching in future development.
Overall, while the plugin avoids common pitfalls like raw SQL or unprotected entry points, the significant output escaping deficiency creates a notable risk. The vulnerability history, though currently clear of active threats, warrants attention to prevent recurrence. Addressing the output escaping issue should be a priority to improve the plugin's security posture.
Key Concerns
- Low percentage of properly escaped output
- Medium severity CVE in vulnerability history
- One external HTTP request
Document & Data Automation Security Vulnerabilities
CVEs by Year
Severity Breakdown
1 total CVE
Document & Data Automation <= 1.6.1 - Cross-Site Request Forgery
Document & Data Automation Release Timeline
Document & Data Automation Code Analysis
SQL Query Safety
Output Escaping
Data Flow Analysis
Document & Data Automation Attack Surface
Shortcodes 4
WordPress Hooks 9
Maintenance & Trust
Document & Data Automation Maintenance & Trust
Maintenance Signals
Community Trust
Document & Data Automation Alternatives
Database for Contact Form 7, WPforms, Elementor forms
contact-form-entries
Saves Contact Form 7, WPforms,Elementor Forms, CRM Perks Forms and many other contact form submissions to database.
BSK PDF Manager
bsk-pdf-manager
Manage your PDFs / documents by category, can be display in list, columns and dropdown. Easy to embed a PDF contnet into post / page.
Ninja Forms Views – Display & Edit Ninja Forms Submissions on your site frontend
views-for-ninja-forms
Display Ninja Forms Submissions on your site frontend using drag & drop View builder.
Views for WPForms – Display & Edit WPForms Entries on your site frontend
views-for-wpforms-lite
Display and Edit WPForms Entries Directly on Your Website with No Coding Knowledge Needed.
WP Max Submit Protect
wp-max-submit-protect
Prevent large forms being submitted that may blow the server's field count limit and lose data.
Document & Data Automation Developer Profile
2 plugins · 2K total installs
How We Detect Document & Data Automation
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/document-data-automation/css/dxosaas.css/wp-content/plugins/document-data-automation/js/iframeResizer.min.js/wp-content/plugins/document-data-automation/js/resizerscript.js/wp-content/plugins/document-data-automation/js/docxpresso_messaging.js/wp-content/plugins/document-data-automation/gutenberg/block.js/wp-content/plugins/document-data-automation/gutenberg/style.css/wp-content/plugins/document-data-automation/js/iframeResizer.min.js/wp-content/plugins/document-data-automation/js/resizerscript.js/wp-content/plugins/document-data-automation/js/docxpresso_messaging.js/wp-content/plugins/document-data-automation/gutenberg/block.jsdocument-data-automation/css/dxosaas.css?ver=document-data-automation/js/iframeResizer.min.js?ver=document-data-automation/js/resizerscript.js?ver=document-data-automation/js/docxpresso_messaging.js?ver=document-data-automation/gutenberg/block.js?ver=document-data-automation/gutenberg/style.css?ver=HTML / DOM Fingerprints
DXOiFrameDXONotifydata-templatedata-namedata-typecontentdata-labeldata-targetdata-form+6 moreDXOptions<div class="DXOiFrame"><iframe<a href=