Eledo PDF Attachments for WooCommerce Security & Risk Analysis

wordpress.org/plugins/eledo-pdf-attachments-for-woocommerce

Automatically generate and attach customizable PDF documents to WooCommerce emails by Payment method.

0 active installs v1.4.0 PHP 5.6+ WP 4.0+ Updated Unknown
emailinvoicespacking-slipspdfwoocommerce
100
A · Safe
CVEs total0
Unpatched0
Last CVENever
Safety Verdict

Is Eledo PDF Attachments for WooCommerce Safe to Use in 2026?

Generally Safe

Score 100/100

Eledo PDF Attachments for WooCommerce has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.

No known CVEs
Risk Assessment

The "eledo-pdf-attachments-for-woocommerce" v1.4.0 plugin exhibits a generally good security posture, with no recorded vulnerabilities and a strong focus on using prepared statements for SQL queries and proper output escaping. The attack surface is remarkably small, with no direct entry points like AJAX handlers, REST API routes, or shortcodes that are exposed without authentication. This indicates a thoughtful approach to limiting potential attack vectors.

However, the static analysis does reveal some areas of concern. Specifically, the taint analysis identified two high-severity flows with unsanitized paths. While these flows didn't reach a critical severity or lead to a direct code execution vulnerability in this version, unsanitized paths can be precursors to file inclusion or path traversal vulnerabilities if not handled meticulously. The presence of file operations (9) also warrants attention in conjunction with these unsanitized paths, suggesting that user-supplied input might be involved in file access or manipulation without adequate sanitization.

Despite these specific concerns, the absence of any known CVEs and the plugin's history of not having reported vulnerabilities are significant strengths. The overall impression is of a plugin with a solid foundation but with a few critical areas in the taint analysis that require immediate developer attention to ensure long-term security.

Key Concerns

  • High severity taint flows with unsanitized paths
  • Unsanitized paths in taint analysis (4 total)
  • SQL queries: 50% not using prepared statements
  • Output escaping: 30% not properly escaped
Vulnerabilities
None known

Eledo PDF Attachments for WooCommerce Security Vulnerabilities

No known vulnerabilities — this is a good sign.
Code Analysis
Analyzed Mar 17, 2026

Eledo PDF Attachments for WooCommerce Code Analysis

Dangerous Functions
0
Raw SQL Queries
3
3 prepared
Unescaped Output
21
50 escaped
Nonce Checks
3
Capability Checks
0
File Operations
9
External Requests
1
Bundled Libraries
0

SQL Query Safety

50% prepared6 total queries

Output Escaping

70% escaped71 total outputs
Data Flows
4 unsanitized

Data Flow Analysis

7 flows4 with unsanitized paths
extra_tablenav (includes\admin\class-eledo-pdf-list-table.php:243)
Source (user input) Sink (dangerous op) Sanitizer Transform Unsanitized Sanitized
Attack Surface

Eledo PDF Attachments for WooCommerce Attack Surface

Entry Points0
Unprotected0
WordPress Hooks 12
filterwoocommerce_settings_tabs_arrayincludes\admin\class-wc-settings-eledo.php:41
actioninitwoocommerce-eledo-pdf-attachments.php:100
actionadmin_initwoocommerce-eledo-pdf-attachments.php:102
actionadmin_enqueue_scriptswoocommerce-eledo-pdf-attachments.php:104
filterwoocommerce_get_settings_pageswoocommerce-eledo-pdf-attachments.php:106
actionplugins_loadedwoocommerce-eledo-pdf-attachments.php:112
actionwoocommerce_admin_order_actions_endwoocommerce-eledo-pdf-attachments.php:114
filterwoocommerce_my_account_my_orders_actionswoocommerce-eledo-pdf-attachments.php:115
actionwp_trash_postwoocommerce-eledo-pdf-attachments.php:117
actionbefore_delete_postwoocommerce-eledo-pdf-attachments.php:118
actionadmin_menuwoocommerce-eledo-pdf-attachments.php:123
filterwoocommerce_email_attachmentswoocommerce-eledo-pdf-attachments.php:125
Maintenance & Trust

Eledo PDF Attachments for WooCommerce Maintenance & Trust

Maintenance Signals

WordPress version tested4.9.29
Last updatedUnknown
PHP min version5.6
Downloads2K

Community Trust

Rating0/100
Number of ratings0
Active installs0
Developer Profile

Eledo PDF Attachments for WooCommerce Developer Profile

husivargal

1 plugin · 0 total installs

94
trust score
Avg Security Score
100/100
Avg Patch Time
30 days
View full developer profile
Detection Fingerprints

How We Detect Eledo PDF Attachments for WooCommerce

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/eledo-pdf-attachments-for-woocommerce/css/eledo.css/wp-content/plugins/eledo-pdf-attachments-for-woocommerce/js/eledo.js/wp-content/plugins/eledo-pdf-attachments-for-woocommerce/js/eledo-admin.js
Script Paths
/wp-content/plugins/eledo-pdf-attachments-for-woocommerce/js/eledo.js/wp-content/plugins/eledo-pdf-attachments-for-woocommerce/js/eledo-admin.js
Version Parameters
eledo-pdf-attachments-for-woocommerce/css/eledo.css?ver=eledo-pdf-attachments-for-woocommerce/js/eledo.js?ver=eledo-pdf-attachments-for-woocommerce/js/eledo-admin.js?ver=

HTML / DOM Fingerprints

CSS Classes
eledo-order-pdf-button
Data Attributes
data-eledo-iddata-eledo-template
JS Globals
eledo_vars
FAQ

Frequently Asked Questions about Eledo PDF Attachments for WooCommerce