EenvoudigFactureren for WooCommerce Security & Risk Analysis

wordpress.org/plugins/eenvoudigfactureren-for-woocommerce

Generate invoices in EenvoudigFactureren for WooCommerce orders.

50 active installs v1.2.2 PHP 7.1+ WP 5.2.0+ Updated Feb 4, 2026
accountingeenvoudigfacturereninvoicewoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is EenvoudigFactureren for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

EenvoudigFactureren for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs Updated 1mo ago
Risk Assessment

The plugin "eenvoudigfactureren-for-woocommerce" v1.2.2 exhibits a generally strong security posture based on the static analysis. The absence of known CVEs and a clean vulnerability history are positive indicators. The code demonstrates good practices by utilizing prepared statements for all SQL queries and performing proper output escaping for the majority of its output. The limited attack surface, with only one AJAX handler and no exposed REST API routes or shortcodes, further reduces the potential for exploitation.

However, the static analysis does reveal a couple of areas that warrant attention. Specifically, the presence of 4 "flows with unsanitized paths" is concerning, even though no critical or high severity issues were flagged in the taint analysis. This suggests that user-supplied data might not be adequately sanitized before being used in certain operations, potentially leading to unintended consequences or future vulnerabilities. Additionally, while there are nonce and capability checks present, the number is relatively low compared to the potential entry points, and the presence of external HTTP requests without explicit mention of authentication or sanitization is another area to monitor.

In conclusion, this plugin appears to be well-developed from a security standpoint, with a solid foundation of secure coding practices. The lack of past vulnerabilities is a significant strength. However, the identified unsanitized paths represent a potential risk that should be investigated and addressed to ensure complete security. The limited number of checks on the single AJAX entry point could also be a minor concern if the sanitization of that handler isn't robust.

Key Concerns

  • Flows with unsanitized paths detected
  • External HTTP requests without explicit security details
  • Low number of capability checks for entry points
Vulnerabilities
None known

EenvoudigFactureren for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 16, 2026

EenvoudigFactureren for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
11
44 escaped
Nonce Checks
3
Capability Checks
2
File Operations
0
External Requests
2
Bundled Libraries
0

Output Escaping

80% escaped55 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

4 flows4 with unsanitized paths
save (admin\api-settings.php:25)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

EenvoudigFactureren for WooCommerce Attack Surface

Entry Points1
Unprotected0

AJAX Handlers 1

authwp_ajax_wcef_new_order_create_documentadmin\column.php:23
WordPress Hooks 10
actionadmin_post_wcef_save_api_settingadmin\api-settings.php:14
filtermanage_edit-shop_order_columnsadmin\column.php:15
actionmanage_shop_order_posts_custom_columnadmin\column.php:16
filterwoocommerce_shop_order_list_table_columnsadmin\column.php:19
actionwoocommerce_shop_order_list_table_custom_columnadmin\column.php:20
actioninitadmin\general-settings.php:14
actionadmin_menuadmin\menu.php:14
actionwoocommerce_thankyouincludes\generation.php:17
actionwoocommerce_order_status_completedincludes\generation.php:18
actionplugins_loadedincludes\loader.php:30
Maintenance & Trust

EenvoudigFactureren for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedFeb 4, 2026
PHP min version7.1
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs50
Developer Profile

EenvoudigFactureren for WooCommerce Developer Profile

Wim Verstuyf

1 plugin · 50 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect EenvoudigFactureren for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eenvoudigfactureren-for-woocommerce/assets/css/admin.css/wp-content/plugins/eenvoudigfactureren-for-woocommerce/assets/js/admin.js
Script Paths
/wp-content/plugins/eenvoudigfactureren-for-woocommerce/assets/js/admin.js
Version Parameters
eenvoudigfactureren-for-woocommerce/assets/css/admin.css?ver=eenvoudigfactureren-for-woocommerce/assets/js/admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
wcef_documentcreate-document-button-primary
Data Attributes
id="create-document-nonce="wcef_create_doc"
JS Globals
ajaxurl
REST Endpoints
/wp-json/wcef_new_order_create_document
FAQ

Frequently Asked Questions about EenvoudigFactureren for WooCommerce